CERT-FR Flags Two Windows Privilege-Escalation CVEs
CERT-FR advisory warns of two Microsoft Windows vulnerabilities allowing privilege escalation and data confidentiality breaches across nearly all Windows/Server versions.
CERT-FR published an advisory describing two vulnerabilities affecting a broad range of Microsoft Windows client and server products, including Windows 10, Windows 11 (through pre-release 26H1), Windows Server 2012 through 2025, and Windows App for Mac. The flaws, tracked as CVE-2026-62727 and CVE-2026-69550, allow an attacker to achieve privilege escalation and compromise data confidentiality. No details on exploitation vector, prerequisites, or in-the-wild exploitation are provided in the advisory.
Microsoft released patches for both CVEs as part of its August 11, 2026 security bulletin, and CERT-FR directs affected organizations to apply the vendor-supplied fixes referenced in the official Microsoft Security Response Center update guide. Given the extensive list of affected product versions spanning over a decade of Windows releases, timely patching is recommended across enterprise environments, though the advisory does not indicate active exploitation.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1060
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free