VORANT. Threat Intelligence Sign in Get the full feed

CPython Windows flaw allows policy bypass

medium vulnerability

A vulnerability in CPython for Windows versions 3.11.x through 3.15.x enables attackers to bypass security policies and compromise data confidentiality.

The French CERT (CERT-FR) has disclosed a security vulnerability affecting CPython for Windows across versions 3.11.x to 3.15.x. The flaw, tracked as CVE-2026-12003, allows an attacker to circumvent security policies and compromise the confidentiality of data on affected systems.

The vulnerability represents a risk to organizations running Python applications on Windows platforms within the affected version range. The Python security team has released patches to address this issue, and affected users are advised to apply the latest security updates immediately.

Organizations should prioritize updating their CPython installations on Windows systems, particularly in production environments where Python is used for critical applications or data processing. The advisory emphasizes both the confidentiality impact and the ability to bypass security controls as primary concerns.

Mentioned in this report

Vulnerabilities CVE-2026-12003

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0790

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free