Windows 11 zero-day lets attackers crash your PC

Published September 1, 2026 CVE-2026-83549

A newly listed security flaw in Windows 11 can be used to crash the operating system. Microsoft and researchers have not yet published details on how an attacker triggers it.

Severity
HighCVSS 3.1 · 7.8
Fix
Update availableFix recorded on Sep 2, 2026
Affected versions
12.4.3-03453 (platform-hotfix) and older versions; 12.5.0-02835 (platform-hotfix) and older versions
Weakness
CWE-78OS Command Injection
Exploit likelihood
8.5% in 30 daysEPSS, higher than 95% of known flaws
Affects
SMA1000
Exploited
Yes, in the wildListed by CISA
Added to CISA list
Sep 2, 2026
Federal fix deadline
Sep 5, 2026

How it works

Someone can send crafted requests to Windows until Windows stops responding.

What to do

There is no public technical writeup yet, so you cannot check for a specific vulnerable build; open Settings, then Windows Update, to see your current build number.

No fixed version or patch has been named publicly yet, so keep Windows Update turned and install the next cumulative update as soon as it is offered, then watch Microsoft's own security update guide for this entry.

Technical details

Affected software: SMA1000by SonicWall

CVE-2026-83549 has been added to VulnCheck's Known Exploited Vulnerabilities list with a high severity rating and is described as a Windows 11 zero-day that causes a crash. As of this writing, NVD and other vulnerability trackers have not yet populated a technical description, affected version range, or fixed build for this CVE, and no vendor advisory text was found in public search results. Because no root cause, attack vector, or proof-of-concept has been published, this entry should be treated as an early listing to watch rather than a fully documented advisory.

Severity breakdown

  • Attack vector Local Needs local access to the machine
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required Low Attacker needs a basic user account
  • User interaction None No victim action needed
  • Scope Unchanged Impact stays within the same security authority
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculator