CVE-2026-69744
massUnauthenticated Null Pointer Dereference DoS in Windows Kerberos
CVE-2026-69744 is a null pointer dereference (CWE-476) in Windows Kerberos, Microsoft's core network authentication protocol, which is enabled by default on Windows domain controllers. A remote, unauthenticated attacker can trigger the flaw by sending specially crafted Kerberos network traffic to a vulnerable host, causing a null pointer dereference that crashes the affected service. The impact is denial of service only — availability is affected (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N, C:N/I:N/A:H); there is no indication of code execution or information disclosure. Any organization running a Windows domain with Kerberos authentication is potentially affected, with domain controllers being the most consequential targets since their Kerberos service outage can block authentication domain-wide. As of now there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a 1.1% probability of exploitation within 30 days (65th percentile), so no in-the-wild exploitation is currently reported.
What to do: Apply the security update for CVE-2026-69744 from Microsoft as soon as it is available for your Windows versions, prioritizing domain controllers. In the interim, limit network access to the Kerberos service (TCP/UDP 88) from untrusted networks and check whether any domain controllers are internet-exposed or reachable through VPN/edge paths. Monitor Microsoft's advisory for the definitive list of affected Windows versions and monitor Kerberos service health for unexplained crashes.
| Microsoft Windows Kerberos (Windows) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Null pointer dereference in Windows Kerberos allows an unauthorized attacker to deny service over a network.
- Weakness
- CWE-476
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.