Format String Information Disclosure in Microsoft Active Directory Certificate Services
AI analysis
CVE-2026-69395 is an externally-controlled format string flaw (CWE-134) in Active Directory Certificate Services (AD CS), the Microsoft Windows Server role that issues and manages digital certificates for an Active Directory environment. An attacker with low-level authorized access — i.e., a valid authenticated account — can send crafted format-string input to the AD CS service over the network, causing the service to misinterpret that input and leak information. Per the CVSS score of 6.5, the impact is limited to confidentiality: the attacker can disclose sensitive service or process information but cannot alter data or disrupt the service. Any organization running the AD CS role on Windows Server is potentially affected, which includes a large share of enterprise Active Directory deployments. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.9% chance of exploitation in the next 30 days; the issue is addressed in Microsoft's September 2026 Patch Tuesday release.
What to do: Install the September 2026 Microsoft security updates on every server running the AD CS role, prioritizing CAs reachable by broad groups of authenticated users. Review whether AD CS network endpoints (such as Web Enrollment or enrollment web services) are exposed to less-trusted network segments and restrict access to them. Monitor Microsoft's advisory for the precise list of affected Windows Server versions, since version details are not included in the data available here.
Affected
| Microsoft Active Directory Certificate Services (AD CS) role on Windows Server | — |
Estimated exposure
mass≈1M+ AD CS server instances worldwide (AD CS ships with Windows Server and is routinely deployed in enterprise Active Directory environments) — AD CS is a built-in Windows Server role deployed in a large fraction of the hundreds of thousands of enterprise Active Directory environments, with one or more CA servers per organization, so the global installed base plausibly exceeds one…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.