Record summary

CVE-2026-56179 has a selected CVSS score of 8.3 (high).

Description

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

Description source: GitHub Advisory

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 13, 2026 · Source: CVE List

Affected products and versions

5
ProductSourceVersion rangeStatus
CVE List10.0.26100.0 to < 10.0.26100.9168affected
CVE List10.0.26200.0 to < 10.0.26200.9168affected
CVE List10.0.28000.0 to < 10.0.28000.2704affected
CVE List10.0.26100.0 to < 10.0.26100.33296affected

Windows Server 2025 (Server Core installation)

Browse Microsoft / Windows Server 2025 (Server Core installation)
CVE List10.0.26100.0 to < 10.0.26100.33296affected

References

2