CVE-2026-27928 | Microsoft Windows Hello Security input validation
A vulnerability, which was classified as critical, was found in Microsoft Windows Server 2016/Server 2019/Server 2022/Server 2022 23H2/Server 2025. Impacted is an unknown function of the component Hello Security. The manipulation results in improper input validation.
This vulnerability is known as CVE-2026-27928. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.