CVE-2025-26685 is an improper authentication vulnerability in Microsoft Defender for Identity, allowing an unauthenticated attacker to spoof identities over an adjacent network. With a CVSS score of 6.5 (Medium), it requires low attack complexity and grants high confidentiality impact without user interaction. While not currently in the KEV catalog and lacking public exploit code, its high community discussion and media coverage indicate significant attention. Organizations should prioritize patching to mitigate the risk of spoofing attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:defender_for_identity:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.