Active Directory Certificate Services (AD CS) Information Disclosure Vulnerability
MonitorCVSS 6.5CVE-2026-69395Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A format string vulnerability in Active Directory Certificate Services allows an authorized attacker to disclose information over a network. The vulnerability requires valid domain credentials and is assessed as unlikely to be exploited. Microsoft has released patches for all affected Windows Server and Windows 10 versions.
What this means
What could happen
An attacker with valid domain credentials could retrieve sensitive information from your AD CS server, such as certificate details or system configuration data. This does not directly compromise operational systems but could expose information used to plan further attacks.
Who's at risk
Organizations running Windows Server with Active Directory Certificate Services enabled. This primarily affects IT infrastructure systems managing certificate lifecycle, but does not directly impact operational control systems unless AD CS is co-hosted with OT infrastructure.
How it could be exploited
An attacker with domain user credentials would send a specially crafted request to AD CS over the network, exploiting a format string vulnerability. The server would return sensitive information in the response.
Prerequisites
- Valid domain user credentials
- Network access to AD CS server (typically port 135, 445, or web services on port 443)
- AD CS role installed on a Windows Server
Requires valid credentials to exploitLow EPSS score (0.9%)
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXApply Windows Server or Windows 10 security update for September 2026 to all affected systems running Windows Server 2016, 2019, 2022, 2025, or Windows 10 Version 1607 or 1809
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/d62cc3b2-657d-41db-af69-1707fd1212d9Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.