DIRAS TAKE
Urgent: this is pre-auth remote code execution with network access required and a CVSS 9.8 rating, so prioritize installing the vendor updates that include the listed fixed builds or else restrict network exposure immediately.
What is CVE-2026-62893?
An unauthenticated attacker can execute code remotely against Windows Server by exploiting a use-after-free flaw in Windows Deployment Services; tracked as CVE-2026-62893. Affected releases include Windows Server 2012 (and Server Core), 2012 R2 (and Server Core), 2016 (and Server Core), 2019 (and Server Core), 2022 and 2025 in the build ranges listed by the vendor; the issue is exploitable over a network and does not require valid credentials or user interaction. The weakness is classified as CWE-416 (Use After Free).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows Server 2012 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows Server 2012 6.x | 6.2.9200.0 – before 6.2.9200.26280 | 6.2.9200.26280 |
| Windows Server 2012 (Server Core installation) 6.x | 6.2.9200.0 – before 6.2.9200.26280 | 6.2.9200.26280 |
| Windows Server 2012 R2 6.x | 6.3.9600.0 – before 6.3.9600.23338 | 6.3.9600.23338 |
| Windows Server 2012 R2 (Server Core installation) 6.x | 6.3.9600.0 – before 6.3.9600.23338 | 6.3.9600.23338 |
| Windows Server 2016 10.x | 10.0.14393.0 – before 10.0.14393.9418 | 10.0.14393.9418 |
| Windows Server 2016 (Server Core installation) 10.x | 10.0.14393.0 – before 10.0.14393.9418 | 10.0.14393.9418 |
| Windows Server 2019 10.x | 10.0.17763.0 – before 10.0.17763.9121 | 10.0.17763.9121 |
| Windows Server 2019 (Server Core installation) 10.x | 10.0.17763.0 – before 10.0.17763.9121 | 10.0.17763.9121 |
| Windows Server 2022 10.x | 10.0.20348.0 – before 10.0.20348.5499 | 10.0.20348.5499 |
| Windows Server 2025 10.x | 10.0.26100.0 – before 10.0.26100.33296 | 10.0.26100.33296 |
Is CVE-2026-62893 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-62893
- Deploy Microsoft's security updates that include the fixed builds (for example 6.2.9200.26280, 6.3.9600.23338, 10.0.14393.9418, 10.0.17763.9121, 10.0.20348.5499, 10.0.26100.33296).
- If you cannot patch immediately, block or limit network access to Windows Deployment Services from untrusted networks.
- Monitor Windows event logs and network traffic for signs of unexpected activity targeting Deployment Services.
- Follow Microsoft guidance for testing and applying the updates in your environment before broad deployment.
Frequently asked questions
Is CVE-2026-62893 being actively exploited?
There are no public reports of active exploitation of CVE-2026-62893 as of 2026-09-29.
Which Windows Server versions are affected by CVE-2026-62893?
Windows Server affected releases cover Windows Server 2012 (and Server Core), 2012 R2 (and Server Core), 2016 (and Server Core), 2019 (and Server Core), 2022 and 2025 within the build ranges listed by Microsoft.
Is there a patch for CVE-2026-62893?
Yes, Microsoft published security updates that fix the issue; fixed builds are provided for each affected branch in Microsoft's advisory.
Does CVE-2026-62893 require authentication?
No, CVE-2026-62893 does not require authentication; an unauthenticated attacker can exploit it over the network.
References
- nvd.nist.gov/vuln/detail/CVE-2026-62893
- cve.org/CVERecord?id=CVE-2026-62893
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62893
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026