CYBERHAWK / CVE / CVE-2026-42902
CVE-2026-42902
HIGH
CVSS 7.8
other
The flaw
Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.
What to do
Review advisory and patch per vendor guidance.
References
In the news
- Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flawsBleepingComputer · 2026-06-09
- Defender under Attack: June's Patch Tuesday in the spotlightthestack.technology · 2026-06-10
- Zero Day Initiative — The June 2026 Security Update Reviewthezdi.com · 2026-06-09