{"schema_version":1,"title":"Samba vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 14 vulnerabilities in Samba: 0 in the last 7 days and 3 in the last 90 days, 4 of them critical and 1 exploited in the wild. The most recent, CVE-2026-58216, was published on 30 July 2026.","url":"https://junglewise.ai/threats/technologies/samba","json_url":"https://junglewise.ai/threats/technologies/samba.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/samba","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":5,"all_time":14,"critical":4,"exploited":1,"last_7_days":0,"last_30_days":0,"last_90_days":3,"last_365_days":11},"latest":[{"cve":"CVE-2026-58216","cvss":5.3,"slug":"cve-2026-58216-samba-kdc-out-of-bounds-read-in-kpasswd-service","title":"Samba KDC out-of-bounds read in kpasswd service","severity":"medium","exploited":false,"published_at":"2026-07-30T16:17:14.767+00:00","url":"https://junglewise.ai/threats/cve-2026-58216-samba-kdc-out-of-bounds-read-in-kpasswd-service"},{"cve":"CVE-2026-58218","cvss":5.3,"slug":"cve-2026-58218-samba-internal-dns-server-denial-of-service-via-tkey-cache","title":"Samba internal DNS server denial of service via TKEY cache exhaustion","severity":"medium","exploited":false,"published_at":"2026-07-30T14:17:00.307+00:00","url":"https://junglewise.ai/threats/cve-2026-58218-samba-internal-dns-server-denial-of-service-via-tkey-cache"},{"cve":"CVE-2026-15779","cvss":6.1,"slug":"cve-2026-15779-samba-pam-winbind-denial-of-service-via-root-directory-chown","title":"Samba pam_winbind denial of service via root directory chown","severity":"medium","exploited":false,"published_at":"2026-07-15T13:17:03.65+00:00","url":"https://junglewise.ai/threats/cve-2026-15779-samba-pam-winbind-denial-of-service-via-root-directory-chown"},{"cve":"CVE-2026-3238","cvss":7.5,"slug":"cve-2026-3238-samba-wins-server-null-pointer-dereference-in-active-directory","title":"Samba WINS server NULL pointer dereference in Active Directory Domain Controller","severity":"high","exploited":false,"published_at":"2026-06-08T09:16:30.16+00:00","url":"https://junglewise.ai/threats/cve-2026-3238-samba-wins-server-null-pointer-dereference-in-active-directory"},{"cve":"CVE-2026-4408","cvss":9,"slug":"cve-2026-4408-samba-command-injection-in-check-password-script","title":"Samba command injection in check password script","severity":"critical","exploited":false,"published_at":"2026-05-28T09:16:47.643+00:00","url":"https://junglewise.ai/threats/cve-2026-4408-samba-command-injection-in-check-password-script"},{"cve":"CVE-2026-2340","cvss":6.5,"slug":"cve-2026-2340-samba-vfs-worm-file-overwrite-via-rename-operation","title":"Samba vfs_worm file overwrite via rename operation","severity":"medium","exploited":false,"published_at":"2026-05-27T14:16:44.387+00:00","url":"https://junglewise.ai/threats/cve-2026-2340-samba-vfs-worm-file-overwrite-via-rename-operation"},{"cve":"CVE-2026-1933","cvss":7.1,"slug":"cve-2026-1933-samba-missing-access-check-on-reparse-point-operations","title":"Samba missing access check on reparse point operations","severity":"high","exploited":false,"published_at":"2026-05-27T14:16:44.023+00:00","url":"https://junglewise.ai/threats/cve-2026-1933-samba-missing-access-check-on-reparse-point-operations"},{"cve":"CVE-2026-3012","cvss":8,"slug":"cve-2026-3012-samba-certificate-auto-enrollment-improper-validation-in-group","title":"Samba certificate auto-enrollment improper validation in Group Policy","severity":"high","exploited":false,"published_at":"2026-05-27T11:16:18.357+00:00","url":"https://junglewise.ai/threats/cve-2026-3012-samba-certificate-auto-enrollment-improper-validation-in-group"},{"cve":"CVE-2026-4480","cvss":8.5,"slug":"cve-2026-4480-samba-remote-code-execution-in-printing-subsystem","title":"Samba remote code execution in printing subsystem","severity":"high","exploited":false,"published_at":"2026-05-26T15:16:40.937+00:00","url":"https://junglewise.ai/threats/cve-2026-4480-samba-remote-code-execution-in-printing-subsystem"},{"cve":"CVE-2025-10230","cvss":10,"epss":0.3899,"slug":"cve-2025-10230-samba-command-injection-in-wins-hook-handling","title":"Samba command injection in WINS hook handling","severity":"critical","exploited":false,"published_at":"2025-11-07T20:15:35.63+00:00","url":"https://junglewise.ai/threats/cve-2025-10230-samba-command-injection-in-wins-hook-handling"},{"cve":"CVE-2025-9640","cvss":4.3,"epss":0.0042,"slug":"cve-2025-9640-samba-uninitialized-memory-disclosure-in-vfs-streams-xattr","title":"Samba uninitialized memory disclosure in vfs_streams_xattr","severity":"medium","exploited":false,"published_at":"2025-10-15T13:16:01.997+00:00","url":"https://junglewise.ai/threats/cve-2025-9640-samba-uninitialized-memory-disclosure-in-vfs-streams-xattr"},{"cve":"CVE-2017-7494","cvss":9.8,"slug":"cve-2017-7494-samba-remote-code-execution-vulnerability","title":"Samba Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2023-03-30T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2017-7494-samba-remote-code-execution-vulnerability"},{"cve":"CVE-1999-0182","cvss":10,"slug":"cve-1999-0182-samba-buffer-overflow-in-password-handling","title":"Samba buffer overflow in password handling","severity":"critical","exploited":false,"published_at":"1997-09-30T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0182-samba-buffer-overflow-in-password-handling"},{"cve":"CVE-1999-0518","cvss":7.5,"slug":"cve-1999-0518-microsoft-windows-and-samba-guessable-netbios-smb-share-password","title":"Microsoft Windows and Samba guessable NetBIOS/SMB share password","severity":"high","exploited":false,"published_at":"1997-01-01T05:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0518-microsoft-windows-and-samba-guessable-netbios-smb-share-password"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Samba","slug":"samba","vendor":{"name":"Samba","slug":"samba","url":"https://junglewise.ai/threats/vendors/samba"},"aliases":[],"category":"library","homepage":"https://www.samba.org/","repo_url":"https://github.com/samba-team/samba","description":"Samba is a free software re-implementation of the SMB/CIFS networking protocol.","url":"https://junglewise.ai/threats/technologies/samba"},"most_severe":[{"cve":"CVE-2017-7494","cvss":9.8,"slug":"cve-2017-7494-samba-remote-code-execution-vulnerability","title":"Samba Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2023-03-30T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2017-7494-samba-remote-code-execution-vulnerability"},{"cve":"CVE-2025-10230","cvss":10,"epss":0.3899,"slug":"cve-2025-10230-samba-command-injection-in-wins-hook-handling","title":"Samba command injection in WINS hook handling","severity":"critical","exploited":false,"published_at":"2025-11-07T20:15:35.63+00:00","url":"https://junglewise.ai/threats/cve-2025-10230-samba-command-injection-in-wins-hook-handling"},{"cve":"CVE-1999-0182","cvss":10,"slug":"cve-1999-0182-samba-buffer-overflow-in-password-handling","title":"Samba buffer overflow in password handling","severity":"critical","exploited":false,"published_at":"1997-09-30T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0182-samba-buffer-overflow-in-password-handling"},{"cve":"CVE-2026-4408","cvss":9,"slug":"cve-2026-4408-samba-command-injection-in-check-password-script","title":"Samba command injection in check password script","severity":"critical","exploited":false,"published_at":"2026-05-28T09:16:47.643+00:00","url":"https://junglewise.ai/threats/cve-2026-4408-samba-command-injection-in-check-password-script"},{"cve":"CVE-2026-4480","cvss":8.5,"slug":"cve-2026-4480-samba-remote-code-execution-in-printing-subsystem","title":"Samba remote code execution in printing subsystem","severity":"high","exploited":false,"published_at":"2026-05-26T15:16:40.937+00:00","url":"https://junglewise.ai/threats/cve-2026-4480-samba-remote-code-execution-in-printing-subsystem"},{"cve":"CVE-2026-3012","cvss":8,"slug":"cve-2026-3012-samba-certificate-auto-enrollment-improper-validation-in-group","title":"Samba certificate auto-enrollment improper validation in Group Policy","severity":"high","exploited":false,"published_at":"2026-05-27T11:16:18.357+00:00","url":"https://junglewise.ai/threats/cve-2026-3012-samba-certificate-auto-enrollment-improper-validation-in-group"},{"cve":"CVE-2026-3238","cvss":7.5,"slug":"cve-2026-3238-samba-wins-server-null-pointer-dereference-in-active-directory","title":"Samba WINS server NULL pointer dereference in Active Directory Domain Controller","severity":"high","exploited":false,"published_at":"2026-06-08T09:16:30.16+00:00","url":"https://junglewise.ai/threats/cve-2026-3238-samba-wins-server-null-pointer-dereference-in-active-directory"},{"cve":"CVE-1999-0518","cvss":7.5,"slug":"cve-1999-0518-microsoft-windows-and-samba-guessable-netbios-smb-share-password","title":"Microsoft Windows and Samba guessable NetBIOS/SMB share password","severity":"high","exploited":false,"published_at":"1997-01-01T05:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0518-microsoft-windows-and-samba-guessable-netbios-smb-share-password"},{"cve":"CVE-2026-1933","cvss":7.1,"slug":"cve-2026-1933-samba-missing-access-check-on-reparse-point-operations","title":"Samba missing access check on reparse point operations","severity":"high","exploited":false,"published_at":"2026-05-27T14:16:44.023+00:00","url":"https://junglewise.ai/threats/cve-2026-1933-samba-missing-access-check-on-reparse-point-operations"},{"cve":"CVE-2026-2340","cvss":6.5,"slug":"cve-2026-2340-samba-vfs-worm-file-overwrite-via-rename-operation","title":"Samba vfs_worm file overwrite via rename operation","severity":"medium","exploited":false,"published_at":"2026-05-27T14:16:44.387+00:00","url":"https://junglewise.ai/threats/cve-2026-2340-samba-vfs-worm-file-overwrite-via-rename-operation"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}