Windows SMB Server Network Transport Driver (srvnet.sys) Denial of Service Vulnerability
Plan PatchCVSS 7.5CVE-2026-72949Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthenticated attacker to crash the SMB service over the network, causing a denial of service.
What this means
What could happen
An attacker could crash the SMB service on your Windows servers, making file shares and other SMB-dependent services temporarily unavailable. This could disrupt access to shared storage, backups, or networked applications that depend on SMB.
Who's at risk
Windows Server administrators and Windows 11 system owners should prioritize this patch. Affected systems include Windows Server 2022, Windows Server 2025, and Windows 11 (all recent versions). Any organization relying on SMB for file sharing, backup transport, or network application communication should apply this update to prevent service disruptions.
How it could be exploited
An attacker sends a specially crafted SMB packet to any Windows system with SMB enabled. No credentials or user interaction are required. The malformed packet triggers a null pointer dereference in srvnet.sys, crashing the SMB driver and causing the service to stop responding.
Prerequisites
- Network access to port 445 (SMB)
- Target must have SMB service enabled (standard on Windows Server and Windows 11)
remotely exploitableno authentication requiredlow complexityaffects file sharing and network services
Exploitability
Some exploitation risk — EPSS score 1.1%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/5
Do now
0/1WORKAROUNDRestrict network access to port 445 (SMB) using firewall rules to only trusted internal networks and systems that require SMB connectivity
Schedule — requires maintenance window
0/3Patching may require device reboot — plan for process interruption
Windows Server 2022
HOTFIXApply the September 2026 security update to Windows Server 2022 (Build 10.0.20348.5622 or later)
Windows Server 2025
HOTFIXApply the September 2026 security update to Windows Server 2025 (Build 10.0.26100.33438 or later)
All products
HOTFIXApply the September 2026 security update to Windows 11 systems (Build 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, or 10.0.28000.2954 depending on version)
Long-term hardening
0/1HARDENINGDisable SMB on systems that do not require file sharing or network communication via SMB
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/c6a3f995-24f3-451b-b17d-e8c4d52d6c31Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.