Windows Server Network driver Remote Code Execution Vulnerability

Plan PatchCVSS 9.8CVE-2026-56188Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A race condition in the Windows network driver allows an unauthorized attacker to execute code over the network. The vulnerability exists in concurrent resource handling where improper synchronization creates a window for exploitation. Affected are Windows 10 versions 1607, 1809, 21H2, and 22H2 across 32-bit, x64, and ARM64 architectures, as well as Windows Server 2016, 2019, 2022, 2025, and Windows 11 versions 24H2, 25H2, and 26H1. Microsoft has issued fixes in the July 2026 security update.

What this means
What could happen
An attacker on the network could exploit a race condition in the Windows network driver to run code with system-level privileges on your Windows servers or workstations, potentially allowing them to install malware, modify critical files, or disrupt services.
Who's at risk
Windows Server administrators managing Windows Server 2016, 2019, 2022, or 2025 installations should prioritize this. Also affects Windows 10 and Windows 11 users, particularly those in networked environments or if running embedded in SCADA/HMI systems. Water utilities and electric utilities running Windows-based engineering workstations, PLCs with Windows runtime environments, or Windows Server-based historians and data repositories are at risk.
How it could be exploited
An attacker sends specially crafted network packets to a vulnerable Windows system. Due to improper synchronization in the network driver, a race condition allows the attacker to execute arbitrary code with system privileges without requiring authentication or user interaction.
Prerequisites
  • Network connectivity to the target system on the network
  • Target system running one of the affected Windows versions without the July 2026 security update
remotely exploitableno authentication requiredlow complexityhigh CVSS score (9.8)affects network infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDImplement network-level filtering to block suspicious traffic patterns if immediate patching is delayed
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXApply the Microsoft July 2026 security update to all affected Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems
Long-term hardening
0/1
HARDENINGIsolate or segment your network to restrict direct network access to Windows servers from untrusted networks or segments
API: /api/v1/advisories/16b0b33f-ccc9-4d78-867f-7ba604b0a2d3

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Server Network driver Remote Code Execution Vulnerability | CVSS 9.8 - OTPulse