• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-49179: unauthenticated command injection in Microsoft Windows 10 Version 1607

An unauthenticated attacker can remotely execute code against Windows Active Directory-related components in multiple Windows releases; see CVE-2026-49179. Affected builds span several Windows 10, Windows 11 and Windows Server 2012 branches (examples include 10.0.14393 before 10.0.14393.9418 and 10.0.19045 before 10.0.19045.7663). The flaw is a command-injection issue (CWE-77) exploitable over a network; the CVSS vector indicates no privileges are required but user interaction is necessary.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
8.8HIGH
EPSS
0.00863
CWE
CWE-77
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code is available, so prioritize patching systems exposed to untrusted networks and apply the listed fixes immediately.

What is CVE-2026-49179?

An unauthenticated attacker can remotely execute code against Windows Active Directory-related components in multiple Windows releases; see CVE-2026-49179. Affected builds span several Windows 10, Windows 11 and Windows Server 2012 branches (examples include 10.0.14393 before 10.0.14393.9418 and 10.0.19045 before 10.0.19045.7663). The flaw is a command-injection issue (CWE-77) exploitable over a network; the CVSS vector indicates no privileges are required but user interaction is necessary. The weakness is classified as CWE-77 (Command Injection).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.941810.0.14393.9418
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.912110.0.17763.9121
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.766310.0.19044.7663
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.766310.0.19045.7663
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.751710.0.22631.7517
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.751710.0.22631.7517
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.916810.0.26100.9168
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.916810.0.26200.9168
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.270410.0.28000.2704
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.262806.2.9200.26280

Is CVE-2026-49179 being exploited?

Public exploit code is available.

How to fix CVE-2026-49179

  1. Apply Microsoft updates that include the fixes (for example: 10.0.14393.9418, 10.0.17763.9121, 10.0.19044.7663, 10.0.19045.7663, 10.0.22631.7517, 10.0.26100.9168, 10.0.26200.9168, 10.0.28000.2704, 6.2.9200.26280).
  2. If you cannot patch immediately, restrict network exposure of affected Windows servers and services to trusted networks only.
  3. Monitor logs and endpoint telemetry for suspicious command execution and unusual process launches on affected hosts.
  4. Follow Microsoft's guidance and update verification steps in your patch management workflow.

Frequently asked questions

Is CVE-2026-49179 being actively exploited?

Public exploit code for CVE-2026-49179 is available.

Which Windows versions are affected by CVE-2026-49179?

Multiple Windows 10 and Windows 11 branches and Windows Server 2012 builds are affected; affected build ranges are listed in vendor advisories (for example 10.0.14393.0–before 10.0.14393.9418 and 10.0.19045.0–before 10.0.19045.7663).

Is there a patch for CVE-2026-49179?

Yes. Microsoft published fixes; patched builds include the fixed versions cited in vendor notes such as 10.0.14393.9418 and 10.0.19045.7663.

Does CVE-2026-49179 require authentication?

No authentication is required to exploit the command-injection flaw, though the CVSS vector indicates user interaction is required.

References