Windows SMBv3 Server Remote Code Execution Vulnerability
Plan PatchCVSS 8.8CVE-2026-62790Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Heap-based buffer overflow in Windows SMB Server that allows an authorized attacker to execute arbitrary code over a network. The vulnerability requires valid credentials but could allow an attacker with domain access to compromise affected servers and execute code with SMB server privileges.
What this means
What could happen
An attacker with valid domain credentials could overflow a buffer in the Windows SMB file-sharing service and run arbitrary code on affected servers, potentially compromising file access, stopping services, or altering data.
Who's at risk
Windows administrators and operators managing Windows Server 2016, 2019, 2022, and 2025 systems, plus Windows 10 and 11 machines if used as file servers or exposed to untrusted networks. Particularly critical for organizations where Windows servers provide file shares, print services, or legacy application access to industrial workstations.
How it could be exploited
An attacker with valid network credentials connects to the SMB service (port 445) on a vulnerable Windows server and sends a crafted SMB packet that triggers a heap-based buffer overflow, allowing code execution with the privileges of the SMB server process.
Prerequisites
- Valid domain or local credentials
- Network access to SMB port 445
- Vulnerable Windows system running SMBv3 server
Requires valid credentials (moderate barrier)Remotely exploitable over networkAffects core file-sharing infrastructureLow exploit complexity
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/2
Do now
0/1HARDENINGRestrict SMB access (port 445/139) to only trusted administrative networks using Windows Firewall or network-layer segmentation
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the 2026-08 Windows security update to all affected systems (see fixed build numbers for your OS version)
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/387abce7-1d45-499e-af5f-1d8aad4c85e2Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.