DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:12:51ZSOURCES: 14CRITICAL: 31
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — Sampled credentials from the FortiBleed dataset and confirmed they are authentic. Many of… /// @MsftSecIntel CRITICAL — Tracking FortiBleed downstream activity. Buyers of the FortiGate credential sets are… /// @TalosSecurity CRITICAL — FortiBleed is just one piece of a broader IAB operation. The same Russian-speaking actor… /// @MalwareHunterTeam CRITICAL — The Gentlemen RaaS internal data leak (May 2026, ~16GB) confirmed operators actively… /// @CrowdStrike CRITICAL — Gentlemen RaaS affiliates are deploying GentleKiller variants that specifically target…
31Critical Threats
18Active CVEs
19IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-45657PUBLISHED: 2026-06-09
CRITICALCVE-2026-45657

Windows Kernel Use-After-Free Unauthenticated RCE (Wormable Candidate)

VENDOR: Microsoft//PRODUCT: Windows Kernel (all supported Windows versions)
9.8
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
NO KNOWN EXPLOIT

CVE-2026-45657 is a use-after-free vulnerability in the Windows Kernel that allows fully unauthenticated remote attackers to execute code at SYSTEM level by sending specially crafted network traffic; no user interaction is required. Zero Day Initiative characterized it as potentially wormable, noting researchers industry-wide were immediately reversing the patch. Microsoft rated it 'Exploitation Less Likely' but ZDI assessed significant real-world risk given the kernel-level SYSTEM impact and no authentication barrier.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSAll supported Windows versions prior to June 2026 Patch Tuesday cumulative update
  • Microsoft MSRC – June 2026 Patch Tuesday
  • Zero Day Initiative – June 2026 Security Update Review: https://www.zerodayinitiative.com/blog/2026/6/9/the-june-2026-security-update-review
  • The Hacker News – Microsoft Patches Record 206 Flaws: https://thehackernews.com/2026/06/microsoft-patches-record-206-flaws.html
  • SOCRadar – June 2026 Patch Tuesday Analysis: https://socradar.io/blog/june-2026-patch-tuesday-zero-day/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn