Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
Plan PatchCVSS 8.8CVE-2026-62818Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A use-after-free memory vulnerability in Active Directory Certificate Services allows an authorized attacker to execute arbitrary code on the server over the network. The vulnerability affects Windows Server 2016, 2019, 2022, and 2025, as well as Windows 10 versions 1607 and 1809. Exploitation requires valid domain credentials. Microsoft rates exploitation as less likely and has released fixes in the August 2026 security update.
What this means
What could happen
An attacker with valid domain credentials could exploit a memory flaw in Active Directory Certificate Services to run arbitrary code on your certificate server, potentially compromising certificate issuance, enabling lateral movement, or disrupting authentication infrastructure.
Who's at risk
Organizations running Windows Server 2016, 2019, 2022, or 2025 with the Active Directory Certificate Services role installed. Also affects Windows 10 Version 1607 and 1809 systems if used for certificate management or AD CS administration. This impacts municipal utilities and water authorities that use AD CS for machine authentication, VPN certificates, or smart meter device identity.
How it could be exploited
An attacker with domain user or elevated credentials connects to your AD CS server over the network and sends a crafted request that triggers the use-after-free vulnerability in certificate processing, allowing code execution on the server.
Prerequisites
- Valid domain user credentials or higher privilege account
- Network access to AD CS server (typically port 135, 445, or 6731 depending on protocol)
- AD CS role installed and running on target Windows server
Remotely exploitable over networkRequires valid domain credentials (not unauthenticated)Low attack complexityAffects identity and access infrastructureEPSS score 0.9% (low but not zero)
Exploitability
Unlikely to be exploited — EPSS score 1.0%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict network access to AD CS servers to only authorized management workstations and trusted domain controllers using Windows Firewall or network segmentation
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply Microsoft 2026-Aug security update to all Windows 10 and Windows Server systems running Active Directory Certificate Services
Long-term hardening
0/1HARDENINGAudit and enforce least-privilege access to AD CS administrative roles; remove unnecessary domain user permissions from certificate server access
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/bca343d1-d5ef-46d2-8e91-f083a2c34134Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.