Published Sunday, August 09, 2026 at 10:17 AM PT

BLUF: Proof-of-concept exploit published for two Windows vulnerabilities (CVE-2026-33825, CVE-2026-41091; CVSS 7.8). PoC exists; vulnerability scope and affected Windows versions NOT confirmed in available sources. Windows administrators should assume increased attack surface and monitor patch status immediately.
DETAILS
- Exploit: “Nightmare-Windows-0-day-exp” PoC published via sploitus; targets two distinct CVEs with shared CVSS score 7.8
- CVE IDs: CVE-2026-33825 and CVE-2026-41091 (both Windows-related; specific vulnerability type not documented in available sources)
- CVSS Rating: 7.8 (high severity; below critical threshold but elevated privilege/impact likely)
- PoC Status: Public proof-of-concept available; weaponization probability HIGH given public disclosure
- Source Attribution: sploitus (exploit aggregator); no official Microsoft advisory detail cross-referenced
IMPACT
- Scope: Unknown. CVE identifiers suggest distinct flaws, but shared CVSS implies comparable blast radius
- Affected: Windows systems matching CVE-2026-33825 and CVE-2026-41091 criteria β version/build details NOT provided in available material
- Risk Window: Immediate. Public PoC + CVSS 7.8 β expect exploitation attempts within hours to days
- Affected Organizations: All Windows infrastructure absent vendor patching
RECOMMENDED ACTIONS
- Immediate: Check Microsoft Security Advisories and CISA alerts for CVE-2026-33825 and CVE-2026-41091 patch/mitigation details (not available in current data)
- Inventory: Identify all Windows systems in scope and current patch levels
- Monitor: Watch for exploitation attempts (lateral movement, privilege escalation post-intrusion) β attack pattern will clarify once PoC is analyzed
- Patch: Apply Microsoft patches immediately upon release; do not deploy until advisory clarifies affected builds
- Contain: If exploited before patching, assume potential for privilege escalation or remote code execution (inferred from CVSS 7.8)
UNCERTAINTY FLAGGED
The following details are NOT confirmed in available sources and must be obtained from official Microsoft/CISA:
- Specific vulnerability type (RCE, privilege escalation, bypass, etc.)
- Affected Windows versions and builds
- Mitigation steps if patches unavailable
- Whether exploits in the wild confirm public PoC works reliably
This alert will be updated upon receipt of official CVE details.
SOURCES
- sploitus (exploit aggregator)
- CVE-2026-33825, CVE-2026-41091 (NVD/Microsoft Security Advisories β pending review)
Status: DEVELOPING. Awaiting Microsoft advisory detail and threat intel on active exploitation.
Recent high-severity events at publish time:

