Windows Kerberos Denial of Service Vulnerability

Plan PatchCVSS 7.5CVE-2026-69760Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

An out-of-bounds read vulnerability exists in the Windows Kerberos authentication component. When processing a specially crafted Kerberos packet, the affected systems read memory beyond the bounds of the intended buffer, causing a denial of service. The Kerberos service may crash, disrupting network authentication for domain-joined machines and preventing legitimate users from logging in or accessing domain resources until the service recovers. The vulnerability affects all commonly deployed Windows versions including Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025.

What this means
What could happen
An attacker can crash domain authentication services on your Windows servers or workstations by sending a specially crafted Kerberos packet, causing temporary unavailability of authentication and domain-dependent applications.
Who's at risk
Windows system administrators and network operators at organizations running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 systems as domain members or domain controllers. This affects all workstations and servers that rely on Kerberos authentication for access control.
How it could be exploited
An attacker sends a malformed Kerberos authentication packet to a Windows machine on your network. The Kerberos service reads memory out of bounds and crashes, denying authentication service to legitimate users and domain services until the machine is rebooted.
Prerequisites
  • Network access to Kerberos authentication port (typically port 88 TCP/UDP)
  • Target must be a Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 system
remotely exploitableno authentication requiredlow complexityaffects authentication infrastructure
Exploitability
Some exploitation risk — EPSS score 1.1%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDImplement network-level access controls to restrict Kerberos traffic (port 88 TCP/UDP) to only authorized domain controllers and trusted subnets
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXApply the September 2026 Windows security update to all Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems
Long-term hardening
0/1
HARDENINGSegment domain authentication infrastructure from untrusted networks using firewall rules
API: /api/v1/advisories/c2db0781-4871-4d91-a64a-a59b5d9a9d4b

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Kerberos Denial of Service Vulnerability | CVSS 7.5 - OTPulse