CVE-2026-72931
Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to deny service locally.
- Published Sep 8, 2026
- CVSS 5.5 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available