Medium severity4.7NVD Advisory· Published Sep 8, 2026
CVE-2026-72931
CVE-2026-72931
Description
Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to deny service locally.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
1- Massive Microsoft Patch Tuesday September 2026 – 973 Vulnerabilities Fixed, Including 2 Zero-DaysCyber Security News · Sep 8, 2026