DIRAS TAKE
Urgent: public exploit code is available, so prioritize patching systems exposed to untrusted networks and apply the listed fixes immediately.
What is CVE-2026-49179?
An unauthenticated attacker can remotely execute code against Windows Active Directory-related components in multiple Windows releases; see CVE-2026-49179. Affected builds span several Windows 10, Windows 11 and Windows Server 2012 branches (examples include 10.0.14393 before 10.0.14393.9418 and 10.0.19045 before 10.0.19045.7663). The flaw is a command-injection issue (CWE-77) exploitable over a network; the CVSS vector indicates no privileges are required but user interaction is necessary. The weakness is classified as CWE-77 (Command Injection).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 10 Version 1607 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1607 10.x | 10.0.14393.0 – before 10.0.14393.9418 | 10.0.14393.9418 |
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9121 | 10.0.17763.9121 |
| Windows 10 Version 21H2 10.x | 10.0.19044.0 – before 10.0.19044.7663 | 10.0.19044.7663 |
| Windows 10 Version 22H2 10.x | 10.0.19045.0 – before 10.0.19045.7663 | 10.0.19045.7663 |
| Windows 11 version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7517 | 10.0.22631.7517 |
| Windows 11 Version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7517 | 10.0.22631.7517 |
| Windows 11 Version 24H2 10.x | 10.0.26100.0 – before 10.0.26100.9168 | 10.0.26100.9168 |
| Windows 11 Version 25H2 10.x | 10.0.26200.0 – before 10.0.26200.9168 | 10.0.26200.9168 |
| Windows 11 version 26H1 10.x | 10.0.28000.0 – before 10.0.28000.2704 | 10.0.28000.2704 |
| Windows Server 2012 6.x | 6.2.9200.0 – before 6.2.9200.26280 | 6.2.9200.26280 |
Is CVE-2026-49179 being exploited?
Public exploit code is available.
How to fix CVE-2026-49179
- Apply Microsoft updates that include the fixes (for example: 10.0.14393.9418, 10.0.17763.9121, 10.0.19044.7663, 10.0.19045.7663, 10.0.22631.7517, 10.0.26100.9168, 10.0.26200.9168, 10.0.28000.2704, 6.2.9200.26280).
- If you cannot patch immediately, restrict network exposure of affected Windows servers and services to trusted networks only.
- Monitor logs and endpoint telemetry for suspicious command execution and unusual process launches on affected hosts.
- Follow Microsoft's guidance and update verification steps in your patch management workflow.
Frequently asked questions
Is CVE-2026-49179 being actively exploited?
Public exploit code for CVE-2026-49179 is available.
Which Windows versions are affected by CVE-2026-49179?
Multiple Windows 10 and Windows 11 branches and Windows Server 2012 builds are affected; affected build ranges are listed in vendor advisories (for example 10.0.14393.0–before 10.0.14393.9418 and 10.0.19045.0–before 10.0.19045.7663).
Is there a patch for CVE-2026-49179?
Yes. Microsoft published fixes; patched builds include the fixed versions cited in vendor notes such as 10.0.14393.9418 and 10.0.19045.7663.
Does CVE-2026-49179 require authentication?
No authentication is required to exploit the command-injection flaw, though the CVSS vector indicates user interaction is required.
References
- nvd.nist.gov/vuln/detail/CVE-2026-49179
- cve.org/CVERecord?id=CVE-2026-49179
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49179
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026