BeyondTrust disclosed two high-severity local vulnerabilities in Endpoint Privilege Management (EPM) for Windows that affect Windows Deployment versions released before 26.1.2. The issues, tracked as CVE-2026-40144 and CVE-2026-40145, were detailed in advisory BT26-04 and echoed in alert AV26-826 from the Canadian Centre for Cyber Security, which urged organizations to review the vendor guidance and apply updates as they become available.
CVE-2026-40144 is a kernel-mode out-of-bounds read flaw that could allow a local non-admin user to corrupt kernel memory and execute arbitrary code in kernel mode, potentially taking full control of an endpoint. CVE-2026-40145 is an insufficient access-control issue in an EPM support utility tied to anti-tamper protections that could let an already privileged local attacker run code outside the intended anti-tamper scope. BeyondTrust said both flaws were fixed in version 26.1.2 and reported no evidence of exploitation before remediation, while recommending prompt upgrades and monitoring for privilege-escalation activity, kernel crashes, suspicious EPM utility behavior, and attempts to disable endpoint security controls.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
On August 18, 2026, the Canadian Centre for Cyber Security published security advisory AV26-826 stating that BeyondTrust Endpoint Privilege Management for Windows was affected by vulnerabilities, with status current as of August 17, 2026. The notice directed users to review BeyondTrust advisory BT26-04 and apply updates as they become available.
BeyondTrust remediated CVE-2026-40144 and CVE-2026-40145 in Endpoint Privilege Management for Windows version 26.1.2. The fixes addressed a kernel-mode out-of-bounds read issue and an insufficient access-control flaw involving a support utility and anti-tamper protections.
On August 17, 2026, BeyondTrust published advisory BT26-04 disclosing two high-severity local vulnerabilities in Endpoint Privilege Management for Windows, tracked as CVE-2026-40144 and CVE-2026-40145. The company said the flaws affected Windows Deployment versions released before 26.1.2 and that it found no evidence of exploitation before remediation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.