Windows SMB Client Remote Code Execution Vulnerability

Plan PatchCVSS 8.1CVE-2026-72936Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary

A use-after-free vulnerability in Windows SMB Client allows an unauthorized attacker to execute arbitrary code over the network without authentication. Affected systems include Windows Server 2022, Windows Server 2025, and Windows 11 (all recent versions across x64 and ARM64 architectures). The vulnerability is in the SMB protocol implementation and can be triggered by sending a specially crafted network packet.

What this means
What could happen
An attacker on the network can trigger a use-after-free flaw in Windows SMB Client to run arbitrary commands on affected servers or workstations, potentially taking control of critical systems or SCADA/HMI servers that rely on Windows.
Who's at risk
Water utilities and electric utilities using Windows Server 2022, Windows Server 2025, or Windows 11 as SCADA workstations, HMI servers, or data historian hosts should prioritize this patch. Any Windows-based engineering workstation, supervisory control server, or network management device is at risk if directly reachable from the network.
How it could be exploited
An attacker sends a specially crafted SMB packet to a Windows device. The SMB Client on the target device processes the malicious packet, triggering a memory corruption flaw that allows the attacker to execute arbitrary code with the privileges of the SMB service. This can happen without user interaction.
Prerequisites
  • Network access to port 445 (SMB) on target Windows device
  • No authentication required
remotely exploitableno authentication requiredaffects Windows servers commonly used in OT environmentsexploitation more likely per advisory
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 23H2 for ARM64-based SystemsAll versionsBuild 10.0.22631.7582
Windows 11 Version 23H2 for x64-based SystemsAll versionsBuild 10.0.22631.7582
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26100.9445
Remediation & Mitigation
0/1
Do now
0/1
HOTFIXApply the 2026-Sep security update to all affected Windows Server and Windows 11 systems immediately
API: /api/v1/advisories/8ed7476c-62c0-4576-a365-f6b96713214a

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.