Microsoft published a security advisory for CVE-2026-40379, a spoofing vulnerability affecting Microsoft Enterprise Security Token Service (ESTS). The flaw is listed in the Microsoft Security Update Guide as an ESTS spoofing issue, indicating a weakness that could allow an attacker to impersonate a trusted identity or service within authentication workflows tied to Microsoft's enterprise token infrastructure.
Public details remain limited, and the advisory entries do not include a technical synopsis, exploitation guidance, or mitigation specifics beyond the vulnerability classification. Even so, the disclosure puts defenders on notice because ESTS underpins identity and token issuance in Microsoft environments, making spoofing risks potentially significant for organizations that rely on Microsoft authentication and access control services.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Microsoft added CVE-2026-40379, a Microsoft Enterprise Security Token Service (ESTS) spoofing vulnerability, to its Security Update Guide. The provided references indicate public disclosure via Microsoft's advisory on this date.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.