ZeroHour

CVE-2026-0386

CVSS 3.1
7.5 high
EPSS
<1%p44
Published
()
Modified
Description

Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.

Vendors
microsoft
Products
windows server 2008, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2022 23h2, windows server 2025
Weakness
CWE-284
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.