Junglewise Threat Intelligence

CVE-2026-26128: Microsoft Windows SMB Server privilege escalation via improper authentication

CVE-2026-26128 · Severity: high · CVSS 7.8 · Published 2026-03-10

Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Windows SMB Server, a component used for sharing files and printers across a network. An attacker who already has basic access to a system could exploit this flaw to gain full administrative control. This could lead to unauthorized access to sensitive data, system-wide changes, or the disruption of business operations.

Technical details

An improper authentication vulnerability (CWE-287) exists in the Microsoft Windows SMB Server. The flaw allows a locally authenticated attacker with low privileges to bypass authentication checks and elevate their status to a higher privilege level, such as SYSTEM. The attack vector is local, meaning the attacker must already have the ability to execute code on the target machine, but no user interaction is required. Microsoft has released security updates to address this issue across multiple versions of Windows and Windows Server.

Affected products

  • Microsoft Windows SMB Server Windows Server 2012, 2016, 2019; Windows 10 (1809, 21H2, 22H2); Windows 11 (23H2, 24H2, 25H2, 26H1)

Timeline

  • 2026-03-10: disclosed
  • 2026-03-10: advisory: Microsoft released the initial advisory and security updates.
  • 2026-05-26: other: NVD record last modified.

References