Record summary

CVE-2026-66802 has a selected CVSS score of 8.1 (high).

Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.

Description source: GitHub Advisory

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2026 · Source: CVE List

Affected products and versions

7
ProductSourceVersion rangeStatus
CVE List10.0.17763.0 to < 10.0.17763.9115affected
CVE List10.0.28000.0 to < 10.0.28000.2704affected
CVE List10.0.17763.0 to < 10.0.17763.9115affected

Windows Server 2019 (Server Core installation)

Browse Microsoft / Windows Server 2019 (Server Core installation)
CVE List10.0.17763.0 to < 10.0.17763.9115affected
CVE List10.0.20348.0 to < 10.0.20348.5499affected
CVE List10.0.26100.0 to < 10.0.26100.33296affected

Windows Server 2025 (Server Core installation)

Browse Microsoft / Windows Server 2025 (Server Core installation)
CVE List10.0.26100.0 to < 10.0.26100.33296affected

References

2