CVE-2026-33826

HIGH

Windows Active Directory Remote Code Execution Vulnerability

Title source: cna

Description

Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.

Exploits (1)

Scores

CVSS v3 8.0
EPSS 0.0044
EPSS Percentile 63.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (16)
microsoft/windows_server_2012 r2
Microsoft/Windows Server 2012 R2 6.3.9600.0 - 6.3.9600.23132
Microsoft/Windows Server 2012 R2 (Server Core installation) 6.3.9600.0 - 6.3.9600.23132
Microsoft/Windows Server 2016 10.0.14393.0 - 10.0.14393.9060
microsoft/windows_server_2016 < 10.0.14393.9060
Microsoft/Windows Server 2016 (Server Core installation) 10.0.14393.0 - 10.0.14393.9060
Microsoft/Windows Server 2019 10.0.17763.0 - 10.0.17763.8644
microsoft/windows_server_2019 < 10.0.17763.8644
Microsoft/Windows Server 2019 (Server Core installation) 10.0.17763.0 - 10.0.17763.8644
Microsoft/Windows Server 2022 10.0.20348.0 - 10.0.20348.5020
... and 6 more
Published Apr 14, 2026
Tracked Since Apr 14, 2026