Active Directory Security Feature Bypass Vulnerability

MonitorCVSS 5.3CVE-2026-65777Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A weakness in Active Directory encryption allows an authorized attacker with valid domain credentials to bypass security features over the network. The vulnerability is in Windows Server 2022, Windows Server 2025, and multiple versions of Windows 11. Exploitation is considered unlikely, and patches are available from Microsoft.

What this means
What could happen
An attacker with valid domain credentials could bypass Active Directory security controls by exploiting weak encryption, potentially allowing unauthorized access to network resources or accounts they should not have permission to access.
Who's at risk
Water and utility organizations using Windows Server 2022 or 2025 as domain controllers or member servers, and those with Windows 11 workstations authenticating to Active Directory. This impacts any facility relying on Windows-based authentication for administrative access to SCADA systems, HMIs, or network infrastructure.
How it could be exploited
An attacker with valid domain user credentials could send specially crafted network requests to an Active Directory server to bypass security features that rely on encryption strength. The attacker must already have legitimate network access and valid credentials to attempt this attack.
Prerequisites
  • Network access to Active Directory servers (typically port 389 or 636)
  • Valid domain user credentials
  • Knowledge of the target Active Directory configuration
remotely exploitablerequires valid credentialsaffects authentication and access control
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows Server 2022All versionsBuild 10.0.20348.5499
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5499
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33296
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9168
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.9168
Windows 11 Version 23H2 for ARM64-based SystemsAll versionsBuild 10.0.22631.7517
Windows 11 Version 23H2 for x64-based SystemsAll versionsBuild 10.0.22631.7517
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9106
Remediation & Mitigation
0/4
Schedule — requires maintenance window
0/3

Patching may require device reboot — plan for process interruption

Windows Server 2022
HOTFIXApply the August 2026 security update to all Windows Server 2022 systems to build 10.0.20348.5499 or later
Windows Server 2025
HOTFIXApply the August 2026 security update to all Windows Server 2025 systems to build 10.0.26100.33296 or later
All products
HOTFIXApply the August 2026 security update to all Windows 11 systems (versions 23H2, 24H2, 25H2, and 26H1) to the corresponding fixed builds
Long-term hardening
0/1
HARDENINGReview Active Directory user accounts and permissions to revoke credentials for unused or dormant accounts
API: /api/v1/advisories/03f445b5-fd94-4adc-8c67-94b640bf1ab1

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Active Directory Security Feature Bypass Vulnerability | CVSS 5.3 - OTPulse