type: cve · created: 2026-09-19 · updated: 2026-09-19 · tags: [cve] · confidence: medium · severity: high · affected_sectors: [global] · au_impact: false
Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.
Two local privilege-escalation bugs were also patched: CVE-2026-62721 (CVSS 7.8) in Windows User-Mode Power Service and CVE-2026-85921 (CVSS 8.2) in Windows Secure Kernel Mode.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-62721 |
| CVSS | 7.8 (high) |
| Vendor / product | Microsoft — Windows User-Mode Power Service (UMPS) |
| Reported | 2026-09-19 |