Skip to main content

CVE-2026-40378

Windows Local Security Authority Subsystem Service (LSASS) Denial of Service vulnerability

Microsoft·Windows Local Security Authority Subsystem Service (LSASS) Denial of Service

MSRC advisory July 14, 2026

Alert details

Source feed
Microsoft MSRC
CVE ID
CVE-2026-40378
Affected products
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service · Microsoft Windows Local Security Authority Subsystem Service (LSASS) Denial of Service · Microsoft

What happened

Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

What it means for your business

Windows Local Security Authority Subsystem Service (LSASS) Denial of Service vulnerability (CVE-2026-40378) was added to Microsoft’s security update guidance. Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

EPSS probability

0.82%

Sources

Related briefs

HighMicrosoft MSRC

CVE-2021-34474

Microsoft Dynamics 365 Business Central Remote Code Execution vulnerability

Microsoft Dynamics 365 Business Central Remote Code Execution vulnerability (CVE-2021-34474) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

MediumMicrosoft MSRC

CVE-2021-36946

Microsoft Dynamics Business Central Cross-site Scripting vulnerability

Microsoft Dynamics Business Central Cross-site Scripting vulnerability (CVE-2021-36946) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

MediumMicrosoft MSRC

CVE-2021-40440

Microsoft Dynamics Business Central Cross-site Scripting vulnerability

Microsoft Dynamics Business Central Cross-site Scripting vulnerability (CVE-2021-40440) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

HighMicrosoft MSRC

CVE-2024-21380

Microsoft Dynamics Business Central/NAV Information Disclosure vulnerability

Microsoft Dynamics Business Central/NAV Information Disclosure vulnerability (CVE-2024-21380) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Need help patching?

PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.