Windows Kerberos Denial of Service Vulnerability
Plan PatchCVSS 7.5CVE-2026-69744Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
A null pointer dereference in Windows Kerberos allows an unauthorized attacker to deny service over the network. An attacker can send a specially crafted network packet to crash the Kerberos authentication service on Windows Server 2025 and Windows 11 systems, preventing users from authenticating and accessing network resources.
What this means
What could happen
An attacker on your network can crash the Kerberos authentication service on Windows servers or workstations, preventing users from logging in or accessing network resources until the system is rebooted.
Who's at risk
Windows Server 2025 installations (both full and Server Core) and Windows 11 systems (versions 24H2 and 25H2, both x64 and ARM64) used as domain controllers, member servers, or workstations in your network infrastructure. This affects any system that runs the Kerberos authentication service, which is critical to user login and network access in Windows domains.
How it could be exploited
An attacker sends a specially crafted network packet to the Kerberos service (port 88) on a vulnerable Windows system. The packet triggers a null pointer dereference in the Kerberos code, causing the authentication service to crash and denying service to legitimate users attempting to authenticate.
Prerequisites
- Network access to port 88 (Kerberos UDP/TCP) on affected Windows systems
- No valid credentials required
- Attacker must be able to reach the target from the network
remotely exploitableno authentication requiredlow complexityaffects critical authentication infrastructure
Exploitability
Some exploitation risk — EPSS score 1.1%
Affected products (6)
6 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/2
Do now
0/1WORKAROUNDRestrict network access to port 88 (Kerberos) to authorized domain controllers and trusted internal networks only; block Kerberos requests from untrusted or external networks at your firewall
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2025
HOTFIXApply the September 2026 Windows security update to all affected systems (Windows Server 2025, Windows 11 Version 24H2, and Windows 11 Version 25H2)
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/d2408c2d-721f-4d4a-9db5-f92151586341Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.