Windows SMBv3 Server Remote Code Execution Vulnerability

Plan PatchCVSS 8.8CVE-2026-62800Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. The vulnerability affects multiple versions of Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025.

What this means
What could happen
An authenticated attacker with network access to SMB port 445 could execute arbitrary code with the privileges of the SMB server process, potentially allowing them to modify industrial process configurations, interrupt services, or gain deeper access to networked control systems.
Who's at risk
System administrators and operators managing Windows-based systems in utility and water authority environments should prioritize patching, particularly for servers hosting centralized logging, data aggregation, or control system interfaces that process SMB traffic. Windows Server systems used for process data collection or SCADA integration are of highest concern.
How it could be exploited
An attacker with valid credentials on your network initiates an SMB connection to port 445 on a vulnerable Windows system. The attacker sends a specially crafted SMB packet that triggers a heap buffer overflow in the SMB server, allowing code execution on the target machine.
Prerequisites
  • Valid user credentials on the network
  • Network access to SMB port 445 (TCP)
  • Target system running vulnerable Windows version
Remotely exploitableRequires valid credentialsAffects multiple Windows versions including ServerNo currently active exploitationLow EPSS score indicates low likelihood of exploitation
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDRestrict SMB port 445 access at the firewall to only authorized engineering workstations and administrative systems
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXApply the August 2026 Windows security update to all affected systems (Windows 10, Windows 11, Windows Server 2016/2019/2022/2025)
All products
HARDENINGDisable SMB v1 if not required for legacy equipment compatibility
Long-term hardening
0/1
HARDENINGImplement network segmentation to isolate OT systems from general IT networks
API: /api/v1/advisories/d6fb5c15-640a-4467-9982-47328c6f7a20

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows SMBv3 Server Remote Code Execution Vulnerability | CVSS 8.8 - OTPulse