Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability

Plan PatchCVSS 8.8CVE-2026-62818Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A use-after-free memory vulnerability in Active Directory Certificate Services allows an authorized attacker to execute arbitrary code on the server over the network. The vulnerability affects Windows Server 2016, 2019, 2022, and 2025, as well as Windows 10 versions 1607 and 1809. Exploitation requires valid domain credentials. Microsoft rates exploitation as less likely and has released fixes in the August 2026 security update.

What this means
What could happen
An attacker with valid domain credentials could exploit a memory flaw in Active Directory Certificate Services to run arbitrary code on your certificate server, potentially compromising certificate issuance, enabling lateral movement, or disrupting authentication infrastructure.
Who's at risk
Organizations running Windows Server 2016, 2019, 2022, or 2025 with the Active Directory Certificate Services role installed. Also affects Windows 10 Version 1607 and 1809 systems if used for certificate management or AD CS administration. This impacts municipal utilities and water authorities that use AD CS for machine authentication, VPN certificates, or smart meter device identity.
How it could be exploited
An attacker with domain user or elevated credentials connects to your AD CS server over the network and sends a crafted request that triggers the use-after-free vulnerability in certificate processing, allowing code execution on the server.
Prerequisites
  • Valid domain user credentials or higher privilege account
  • Network access to AD CS server (typically port 135, 445, or 6731 depending on protocol)
  • AD CS role installed and running on target Windows server
Remotely exploitable over networkRequires valid domain credentials (not unauthenticated)Low attack complexityAffects identity and access infrastructureEPSS score 0.9% (low but not zero)
Exploitability
Unlikely to be exploited — EPSS score 1.0%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5499
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33296
Windows Server 2025All versionsBuild 10.0.26100.33296
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict network access to AD CS servers to only authorized management workstations and trusted domain controllers using Windows Firewall or network segmentation
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply Microsoft 2026-Aug security update to all Windows 10 and Windows Server systems running Active Directory Certificate Services
Long-term hardening
0/1
HARDENINGAudit and enforce least-privilege access to AD CS administrative roles; remove unnecessary domain user permissions from certificate server access
API: /api/v1/advisories/bca343d1-d5ef-46d2-8e91-f083a2c34134

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability | CVSS 8.8 - OTPulse