CVE-2026-0386
Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.
- Affected products
- Windows
- Microsoft Windows Server 2008
- All versions
- Microsoft Windows Server 2012
- All versions
- Microsoft Windows Server 2016
- < 10.0.14393.8783
- Microsoft Windows Server 2019
- < 10.0.17763.8276
- Microsoft Windows Server 2022
- < 10.0.20348.4648
- Microsoft Windows Server 2022 23h2
- < 10.0.25398.2092
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.6% (45th percentile)
- Weakness
- CWE-284
- NVD status
- Analyzed
- Published
- 2026-01-13
CVE-2026-0386 at NVD
1 known exploit for CVE-2026-0386
Proof-of-concept code and exploit modules indexed by Sploitus