What happened
Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.
Affected versions
Unknown product: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
CVE-Intel · Semperis-Community/ResetNightmarePOC tool for ResetNightmare (CVE-2026-27912)PoCPowerShellHIGHAnalyzed★ 208⑂ 37EPSS 0.41%CVE data: NISTCode indexedUpdated 26 Aug 2026Semperis-Community2026-08-02CandidateCVE-Intel · oxstussz-eng/Kerberos-CVE-2026-27912PoC for CVE-2026-27912 - Windows Kerberos Elevation of Privilege (ResetNightmare). Unauthorized password reset via Kerberos flaw. For security research only.PoCPythonHIGHAnalyzed★ 2⑂ 0EPSS 0.41%CVE data: NISTCode indexedUpdated 23 Aug 2026oxstussz-eng2026-08-14CandidateCVE-Intel · mihat2/ResetNightmare-impacketCVE-2026-27912 (ResetNightmare) — Linux/impacket port of Semperis Community's Invoke-ResetNightmare PoCPoCPythonHIGHAnalyzed★ 4⑂ 4EPSS 0.41%CVE data: NISTCode indexedUpdated 20 Aug 2026Tags: active-directory, active-directory-security, cve, cve-2026-27912, impacket, kadmin-changepw, kerberos, ldapmihat22026-08-08CandidateSource timeline
Discovered through CVE-IntelView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.