Windows Kerberos Remote Code Execution Vulnerability
Plan PatchCVSS 8.8CVE-2026-69676Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A Kerberos authentication bypass vulnerability in Windows allows an authorized user to capture and replay Kerberos authentication traffic to execute code on remote systems without needing the actual password. This affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 across 32-bit, x64, and ARM64 architectures. Microsoft rates exploitation likelihood as more probable and recommends immediate patching.
What this means
What could happen
An authorized user on your network could capture and replay Kerberos authentication traffic to gain unauthorized system access and run commands on Windows workstations or servers, potentially compromising critical infrastructure systems and data.
Who's at risk
Windows system administrators managing Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 in a domain environment. This affects any organization using Windows domain authentication, including water utilities, municipal electric systems, and other critical infrastructure that rely on Windows-based SCADA workstations, engineering terminals, or administrative systems.
How it could be exploited
An attacker with network access to your domain could intercept and replay Kerberos authentication packets between clients and domain controllers. By replaying captured credentials, the attacker could impersonate an authorized user and execute arbitrary commands on Windows systems without needing to know the actual password.
Prerequisites
- Network access to Kerberos traffic (ports 88 TCP/UDP)
- Valid domain user credentials or ability to capture authentication packets in transit
- Access to systems using Kerberos authentication (typically Windows domains)
Remotely exploitableRequires valid domain user credentialsAffects domain-joined systemsKerberos authentication is fundamental to Windows securityHigh CVSS score (8.8)
Exploitability
Some exploitation risk — EPSS score 1.2%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXApply the September 2026 Windows security update to all affected Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems
All products
HOTFIXPrioritize updates for domain controllers and servers that run critical processes
Long-term hardening
0/2HARDENINGSegment network to restrict Kerberos traffic (port 88) to only authorized domain controllers and clients
HARDENINGEnable network traffic encryption between clients and domain controllers if not already configured
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/db9e23e6-5095-4807-835c-0fd1b2189c0eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.