Sploitus

CVE-2026-0386

1 known exploit for CVE-2026-0386

Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.

Affected products
Windows
Microsoft Windows Server 2008
All versions
Microsoft Windows Server 2012
All versions
Microsoft Windows Server 2016
< 10.0.14393.8783
Microsoft Windows Server 2019
< 10.0.17763.8276
Microsoft Windows Server 2022
< 10.0.20348.4648
Microsoft Windows Server 2022 23h2
< 10.0.25398.2092
CVSS 3.1
7.5 HIGH
EPSS
0.6% (45th percentile)
Weakness
CWE-284
NVD status
Analyzed
Published
2026-01-13
CVE-2026-0386 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-0386

Proof-of-concept code and exploit modules indexed by Sploitus