Windows SMB Server Information Disclosure Vulnerability
MonitorCVSS 5.5CVE-2026-69403Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Missing authorization in Windows SMB Server allows an authenticated local attacker to disclose information that should be restricted. The vulnerability affects all supported versions of Windows Server (2016, 2019, 2022, 2025) and Windows 10/11 systems. An attacker with valid user credentials but no administrative rights can exploit this to access sensitive data locally. Microsoft has released security updates for all affected systems.
What this means
What could happen
An authenticated local user can access sensitive information on Windows systems via the SMB Server, potentially exposing cached credentials or configuration data that could be used in further attacks.
Who's at risk
Windows Server systems (2016, 2019, 2022, 2025) and Windows 10/11 workstations used in engineering environments, HMI systems, data historians, and any facility management systems where local user access is provisioned. Any Windows-based control system component or engineering workstation is potentially affected.
How it could be exploited
An attacker with local user account access to a Windows system (such as a contractor workstation or compromised non-admin user) can query the SMB Server to extract information that should be restricted, without requiring administrative privileges. The attack requires only local network access and valid user credentials.
Prerequisites
- Local or domain user account on affected Windows system
- Access to SMB Server on the local system (enabled by default)
- No administrative or special privileges required
Local authentication required but no administrative privilege neededAffects common industrial Windows Server versionsPotential exposure of cached credentials
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXPrioritize patching Windows Server 2016, 2019, and 2022 systems first as these are commonly used in industrial and critical infrastructure environments
All products
HOTFIXApply Microsoft September 2026 security update to all affected Windows systems (see fixed versions in product list)
Long-term hardening
0/1HARDENINGReview and restrict local user account access on engineering workstations and control system servers to minimize risk from compromised low-privilege accounts
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/cd2dcf11-362e-4b72-880e-8875e5072b33Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.