ZeroHour

CVE-2026-69395

mass

Format String Information Disclosure in Microsoft Active Directory Certificate Services

CVSS 3.1
6.5 medium
EPSS
<1%p57
Published
()
Modified
AI analysis

CVE-2026-69395 is an externally-controlled format string flaw (CWE-134) in Active Directory Certificate Services (AD CS), the Microsoft Windows Server role that issues and manages digital certificates for an Active Directory environment. An attacker with low-level authorized access — i.e., a valid authenticated account — can send crafted format-string input to the AD CS service over the network, causing the service to misinterpret that input and leak information. Per the CVSS score of 6.5, the impact is limited to confidentiality: the attacker can disclose sensitive service or process information but cannot alter data or disrupt the service. Any organization running the AD CS role on Windows Server is potentially affected, which includes a large share of enterprise Active Directory deployments. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.9% chance of exploitation in the next 30 days; the issue is addressed in Microsoft's September 2026 Patch Tuesday release.

What to do: Install the September 2026 Microsoft security updates on every server running the AD CS role, prioritizing CAs reachable by broad groups of authenticated users. Review whether AD CS network endpoints (such as Web Enrollment or enrollment web services) are exposed to less-trusted network segments and restrict access to them. Monitor Microsoft's advisory for the precise list of affected Windows Server versions, since version details are not included in the data available here.

Affected
Microsoft Active Directory Certificate Services (AD CS) role on Windows Server
Estimated exposure
mass≈1M+ AD CS server instances worldwide (AD CS ships with Windows Server and is routinely deployed in enterprise Active Directory environments) — AD CS is a built-in Windows Server role deployed in a large fraction of the hundreds of thousands of enterprise Active Directory environments, with one or more CA servers per organization, so the global installed base plausibly exceeds one…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacker to disclose information over a network.

Weakness
CWE-134
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Microsoft's September 2026 Patch Tuesday fixes a record 966 flaws, including two Windows zero-days actively exploited to gain SYSTEM privileges.

Microsoft's September 2026 Patch Tuesday addresses a record 966 vulnerabilities, including 105 rated Critical, 81 of them remote code execution bugs. Two zero-days were actively exploited: a Windows Update Stack link-following flaw and a Windows ALPC heap-based buffer overflow, both allowing local elevation to SYSTEM privileges. The ALPC flaw was reported by Volexity and Proofpoint researchers, while the Update Stack flaw was credited to Romain Deperne and the Microsoft Threat Intelligence Centre. Microsoft shared no details on how the flaws were exploited in attacks.

BleepingComputer · 7d agoAdvisory in the wildCVE-2026-69805CVE-2026-58649CVE-2026-69806+27 CVEs1