Active Directory Security Feature Bypass Vulnerability
MonitorCVSS 5.3CVE-2026-65777Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary
A weakness in Active Directory encryption allows an authorized attacker with valid domain credentials to bypass security features over the network. The vulnerability is in Windows Server 2022, Windows Server 2025, and multiple versions of Windows 11. Exploitation is considered unlikely, and patches are available from Microsoft.
What this means
What could happen
An attacker with valid domain credentials could bypass Active Directory security controls by exploiting weak encryption, potentially allowing unauthorized access to network resources or accounts they should not have permission to access.
Who's at risk
Water and utility organizations using Windows Server 2022 or 2025 as domain controllers or member servers, and those with Windows 11 workstations authenticating to Active Directory. This impacts any facility relying on Windows-based authentication for administrative access to SCADA systems, HMIs, or network infrastructure.
How it could be exploited
An attacker with valid domain user credentials could send specially crafted network requests to an Active Directory server to bypass security features that rely on encryption strength. The attacker must already have legitimate network access and valid credentials to attempt this attack.
Prerequisites
- Network access to Active Directory servers (typically port 389 or 636)
- Valid domain user credentials
- Knowledge of the target Active Directory configuration
remotely exploitablerequires valid credentialsaffects authentication and access control
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Schedule — requires maintenance window
0/3Patching may require device reboot — plan for process interruption
Windows Server 2022
HOTFIXApply the August 2026 security update to all Windows Server 2022 systems to build 10.0.20348.5499 or later
Windows Server 2025
HOTFIXApply the August 2026 security update to all Windows Server 2025 systems to build 10.0.26100.33296 or later
All products
HOTFIXApply the August 2026 security update to all Windows 11 systems (versions 23H2, 24H2, 25H2, and 26H1) to the corresponding fixed builds
Long-term hardening
0/1HARDENINGReview Active Directory user accounts and permissions to revoke credentials for unused or dormant accounts
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/03f445b5-fd94-4adc-8c67-94b640bf1ab1Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.