CVE- 2026-27912, known as ResetNightmare, is a high-severity vulnerability in the Windows Kerberos Change Password protocol allowing attackers to reset any Active Directory account password without knowing the old password, potentially granting SYSTEM privileges. The vulnerability has a CVSS score of 8.0 and affects specific versions of Microsoft Windows Server.
Microsoft has released patches, and while no confirmed exploitation has been reported, the publication of proof-of-concept exploit tools heightens risks for unpatched domain controllers. Administrators are advised to update their systems immediately.