Windows Active Directory Domain Services Remote Code Execution Vulnerability
Plan PatchCVSS 8.1CVE-2026-69524Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary
A use-after-free vulnerability in Active Directory Domain Services allows an unauthenticated attacker to execute code over the network on affected systems. This impacts Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025. Exploitation is assessed as unlikely, but Microsoft recommends immediate patching.
What this means
What could happen
An attacker could execute arbitrary code on a domain controller or domain-joined server, potentially gaining full control of Active Directory and the ability to compromise all systems in the domain.
Who's at risk
This affects any organization using Windows Active Directory, including all mid-size to large utilities, municipalities, and enterprises with Windows domain infrastructure. Both domain controllers and domain-joined servers (workstations, member servers, application servers) running Windows Server 2016, 2019, 2022, 2025 or Windows 10/11 are at risk.
How it could be exploited
An attacker on the network sends a specially crafted request to the Active Directory Domain Services component (typically port 389 LDAP or 3268 Global Catalog). The use-after-free vulnerability allows code execution without authentication. Once executed on a domain controller, the attacker gains the privileges of the AD service.
Prerequisites
- Network access to LDAP port 389 or Global Catalog port 3268 on a domain controller or domain-joined server
- Windows Server 2016, 2019, 2022, 2025, or Windows 10/11 with Active Directory Domain Services enabled or domain membership
remotely exploitableno authentication requiredaffects critical directory servicehigh CVSS score (8.1)
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict network access to LDAP ports (389, 636) and Global Catalog ports (3268, 3269) to only authorized management systems and domain-joined computers
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the 2026-Sep (September 2026) security update to all domain controllers and domain-joined servers
Long-term hardening
0/1HARDENINGMonitor LDAP traffic to domain controllers for suspicious or unexpected connection attempts
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/731d1d7e-5867-4a52-a550-f38935e96daeGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.