Windows SMB Client Remote Code Execution Vulnerability
Plan PatchCVSS 8.1CVE-2026-72936Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary
A use-after-free vulnerability in Windows SMB Client allows an unauthorized attacker to execute arbitrary code over the network without authentication. Affected systems include Windows Server 2022, Windows Server 2025, and Windows 11 (all recent versions across x64 and ARM64 architectures). The vulnerability is in the SMB protocol implementation and can be triggered by sending a specially crafted network packet.
What this means
What could happen
An attacker on the network can trigger a use-after-free flaw in Windows SMB Client to run arbitrary commands on affected servers or workstations, potentially taking control of critical systems or SCADA/HMI servers that rely on Windows.
Who's at risk
Water utilities and electric utilities using Windows Server 2022, Windows Server 2025, or Windows 11 as SCADA workstations, HMI servers, or data historian hosts should prioritize this patch. Any Windows-based engineering workstation, supervisory control server, or network management device is at risk if directly reachable from the network.
How it could be exploited
An attacker sends a specially crafted SMB packet to a Windows device. The SMB Client on the target device processes the malicious packet, triggering a memory corruption flaw that allows the attacker to execute arbitrary code with the privileges of the SMB service. This can happen without user interaction.
Prerequisites
- Network access to port 445 (SMB) on target Windows device
- No authentication required
remotely exploitableno authentication requiredaffects Windows servers commonly used in OT environmentsexploitation more likely per advisory
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Do now
0/1HOTFIXApply the 2026-Sep security update to all affected Windows Server and Windows 11 systems immediately
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/8ed7476c-62c0-4576-a365-f6b96713214aGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.