Technology · Samba
Samba vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 14 vulnerabilities in Samba: 0 in the last 7 days and 3 in the last 90 days, 4 of them critical and 1 exploited in the wild. The most recent, CVE-2026-58216, was published on 30 July 2026.
- Last 7 days
- 0
- Last 90 days
- 3
- Critical, all time
- 4
- Exploited in the wild
- 1
About Samba
Samba is a free software re-implementation of the SMB/CIFS networking protocol.
Latest Samba vulnerabilities
- CVE-2026-58216: Samba KDC out-of-bounds read in kpasswd servicemediumCVSS 5.3
- CVE-2026-58218: Samba internal DNS server denial of service via TKEY cache exhaustionmediumCVSS 5.3
- CVE-2026-15779: Samba pam_winbind denial of service via root directory chownmediumCVSS 6.1
- CVE-2026-3238: Samba WINS server NULL pointer dereference in Active Directory Domain ControllerhighCVSS 7.5
- CVE-2026-4408: Samba command injection in check password scriptcriticalCVSS 9
- CVE-2026-2340: Samba vfs_worm file overwrite via rename operationmediumCVSS 6.5
- CVE-2026-1933: Samba missing access check on reparse point operationshighCVSS 7.1
- CVE-2026-3012: Samba certificate auto-enrollment improper validation in Group PolicyhighCVSS 8
- CVE-2026-4480: Samba remote code execution in printing subsystemhighCVSS 8.5
- CVE-2025-10230: Samba command injection in WINS hook handlingcriticalCVSS 10EPSS 39.0%
- CVE-2025-9640: Samba uninitialized memory disclosure in vfs_streams_xattrmediumCVSS 4.3EPSS 0.4%
- CVE-2017-7494: Samba Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-1999-0182: Samba buffer overflow in password handlingcriticalCVSS 10
- CVE-1999-0518: Microsoft Windows and Samba guessable NetBIOS/SMB share passwordhighCVSS 7.5
Most severe Samba vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2017-7494: Samba Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2025-10230: Samba command injection in WINS hook handlingcriticalCVSS 10EPSS 39.0%
- CVE-1999-0182: Samba buffer overflow in password handlingcriticalCVSS 10
- CVE-2026-4408: Samba command injection in check password scriptcriticalCVSS 9
- CVE-2026-4480: Samba remote code execution in printing subsystemhighCVSS 8.5
- CVE-2026-3012: Samba certificate auto-enrollment improper validation in Group PolicyhighCVSS 8
- CVE-2026-3238: Samba WINS server NULL pointer dereference in Active Directory Domain ControllerhighCVSS 7.5
- CVE-1999-0518: Microsoft Windows and Samba guessable NetBIOS/SMB share passwordhighCVSS 7.5
- CVE-2026-1933: Samba missing access check on reparse point operationshighCVSS 7.1
- CVE-2026-2340: Samba vfs_worm file overwrite via rename operationmediumCVSS 6.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 2 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/samba.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Samba vulnerabilities", https://junglewise.ai/threats/technologies/samba, 26 September 2026.