ANDROID RugOne Xsnap 7 Pro Launches with Detachable Action Camera for $999 GAMES EA FC 27 Web App Release Date Approaches for Ultimate Team GAMES Sega Redefines Gamers: Like a Dragon Fans Watch Streams Without Playing DLSS DLSS 5 Mod Boosts RTX 5080 Frames by 61% in Assassin’s Creed Shadows AMD NeuralScreen Brings DLSS 5 Neural Rendering to Windows 11 Desktop NINTENDO Zelda Ocarina of Time 3D Remake Price Leaked at $60 USD ACCESSORIES IKEA Dubbelkisel Driver Adds Matter Wireless Control to Smart Lighting NINTENDO Lego Zelda Link & Epona Set Announced for Spring 2027 GAMES Roco Kingdom Closed Beta Test Now Open for Sign-Up NINTENDO Aniimo Not Free-to-Play: Pre-Order Tiers and Rewards Explained GAMES GTA 5 Voice Actor Ned Luke Plans Final Playthrough Before GTA 6 Launch GAMES Marvel Rivals Season 10 Trailer Confirms Gorr The God Butcher GAMES Path of Exile co-creator admits to planting fake assets to troll dataminers GAMES The Outlast Trials Chemical Leak Update Hits Sept 8

Microsoft Patches Passkey Flaw CVE-2026-34348 in Windows 11

Owen Carter 2 min read

Microsoft patched CVE- 2026- 34348, a passkey reuse vulnerability in Windows 11 and Entra ID, to prevent credential replay attacks in enterprise environments.

Microsoft Patches Passkey Flaw CVE-2026-34348 in Windows 11
SOFTWARE AND UPDATES

Microsoft closed a critical security gap in its passkey infrastructure on July 14. This patch protects enterprise environments from attacks that bypass traditional password requirements. Users relying on FIDO2 keys for single sign-on now have a verified fix for a flaw that allowed credential reuse.

Enterprise identity management requires strict enforcement of modern authentication standards

The vulnerability, tracked as CVE-2026-34348, targeted the interaction between Windows 11 and Microsoft Entra ID. Security researcher Michael Grafnetter demonstrated how an attacker could exploit this setup during a presentation at Black Hat USA. The attack, dubbed 'Pass-the-Passkey,' allowed unauthorized access without the victim's actual password.

Grafnetter found that Windows 11 logged full copies of passkey material, creating a local security risk. Microsoft Entra ID failed to prevent the reuse of these captured keys across different sessions. The cloud-side flaw specifically enabled attackers to replay valid authentication tokens generated by legitimate users.

Microsoft addressed the cloud-side vulnerability on July 14 to stop the token replay attacks. The fix primarily impacts enterprise deployments that use Entra ID for identity management. Organizations should verify that their FIDO2 key implementations are updated to prevent legacy password logins.

Passkeys remain a more secure alternative to passwords when configured correctly. The vulnerability highlights the need for strict enforcement of modern authentication standards. Enterprises must disable legacy password options to fully benefit from the security improvements.

Source: Pass-the-Passkey, NotebookCheck