High severity7.0NVD Advisory· Published Sep 8, 2026
CVE-2026-69398
CVE-2026-69398
Description
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
1- Massive Microsoft Patch Tuesday September 2026 – 973 Vulnerabilities Fixed, Including 2 Zero-DaysCyber Security News · Sep 8, 2026