PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-48575 Microsoft CVE debrief

A protection mechanism failure in Windows Secure Boot, tracked as CVE-2026-48575, allows an authorized attacker to bypass a security feature locally. This vulnerability has a CVSS score of 7.9, indicating a high severity level. The vulnerability was published on 2026-06-09T17:17:46.200Z and modified on 2026-06-10T15:15:32.757Z.

Vendor
Microsoft
Product
Windows 10 Version 1607
CVSS
HIGH 7.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-09
Original CVE updated
2026-06-10
Advisory published
2026-06-09
Advisory updated
2026-06-10

Who should care

Administrators and users of affected Microsoft Windows versions should prioritize patching this vulnerability to prevent potential local attacks.

Technical summary

The vulnerability, CVE-2026-48575, is caused by a protection mechanism failure in Windows Secure Boot. This allows an authorized attacker to bypass a security feature locally. The CVSS vector for this vulnerability is CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N.

Defensive priority

High

Recommended defensive actions

  • Apply patches from Microsoft as soon as possible.
  • Review and update Secure Boot configurations to ensure they are properly set up and enforced.
  • Monitor systems for any suspicious activity that could indicate exploitation attempts.

Evidence notes

The CVE record and details are sourced from official databases and vendor advisories.

Official resources

CVE-2026-48575 was published on 2026-06-09T17:17:46.200Z and modified on 2026-06-10T15:15:32.757Z.