Windows SMB Server Network Transport Driver (srvnet.sys) Denial of Service Vulnerability

Plan PatchCVSS 7.5CVE-2026-72949Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthenticated attacker to crash the SMB service over the network, causing a denial of service.

What this means
What could happen
An attacker could crash the SMB service on your Windows servers, making file shares and other SMB-dependent services temporarily unavailable. This could disrupt access to shared storage, backups, or networked applications that depend on SMB.
Who's at risk
Windows Server administrators and Windows 11 system owners should prioritize this patch. Affected systems include Windows Server 2022, Windows Server 2025, and Windows 11 (all recent versions). Any organization relying on SMB for file sharing, backup transport, or network application communication should apply this update to prevent service disruptions.
How it could be exploited
An attacker sends a specially crafted SMB packet to any Windows system with SMB enabled. No credentials or user interaction are required. The malformed packet triggers a null pointer dereference in srvnet.sys, crashing the SMB driver and causing the service to stop responding.
Prerequisites
  • Network access to port 445 (SMB)
  • Target must have SMB service enabled (standard on Windows Server and Windows 11)
remotely exploitableno authentication requiredlow complexityaffects file sharing and network services
Exploitability
Some exploitation risk — EPSS score 1.1%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 23H2 for ARM64-based SystemsAll versionsBuild 10.0.22631.7582
Windows 11 Version 23H2 for x64-based SystemsAll versionsBuild 10.0.22631.7582
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26100.9445
Remediation & Mitigation
0/5
Do now
0/1
WORKAROUNDRestrict network access to port 445 (SMB) using firewall rules to only trusted internal networks and systems that require SMB connectivity
Schedule — requires maintenance window
0/3

Patching may require device reboot — plan for process interruption

Windows Server 2022
HOTFIXApply the September 2026 security update to Windows Server 2022 (Build 10.0.20348.5622 or later)
Windows Server 2025
HOTFIXApply the September 2026 security update to Windows Server 2025 (Build 10.0.26100.33438 or later)
All products
HOTFIXApply the September 2026 security update to Windows 11 systems (Build 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, or 10.0.28000.2954 depending on version)
Long-term hardening
0/1
HARDENINGDisable SMB on systems that do not require file sharing or network communication via SMB
API: /api/v1/advisories/c6a3f995-24f3-451b-b17d-e8c4d52d6c31

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows SMB Server Network Transport Driver (srvnet.sys) Denial of Service Vulnerability | CVSS 7.5 - OTPulse