Medium 6.5
CVE-2026-34348
Pass-the-Passkey Attacks Bypass MFA in Windows and Entra ID
Vendor / product: Windows 11, Microsoft Entra ID, Google Password Manager, Windows Hello for Business
Event date: 2026-07-14
Public PoC: Yes
First tracked by RiskWire: 2026-07-28
Sources & citations (3)
- Pass-the-Passkey Attack Exploits Windows and Entra ID to Bypass MFA gbhackers.com · 2026-08-11
- New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA thehackernews.com · 2026-08-10
- Pass-the-Passkey Attacks Expose Windows 11 and Microsoft Entra ID, Bypassing MFA cybersecuritynews.com · 2026-08-10
References
See CVE-2026-34348 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →