• PATCH AVAILABLE

CVE-2026-78445: pre-auth remote code execution in Microsoft Windows Server 2012

An unauthenticated attacker can execute arbitrary code on Windows Server via a use-after-free flaw in the Services for NFS ONCRPC XDR driver (CVE-2026-78445). Affected products include Windows Server 2012 and 2012 R2, Windows Server 2016, 2019, 2022 and 2025 builds listed as before their respective fixed builds; the vendor published updates that correct the vulnerable builds. Exploitation requires network access to the affected service and does not require valid credentials.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-416
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: deploy Microsoft's updates immediately because this is a remote, unauthenticated code-execution flaw that allows attackers to run code over the network. Prioritise internet-facing or NFS-exposed servers first.

What is CVE-2026-78445?

An unauthenticated attacker can execute arbitrary code on Windows Server via a use-after-free flaw in the Services for NFS ONCRPC XDR driver (CVE-2026-78445). Affected products include Windows Server 2012 and 2012 R2, Windows Server 2016, 2019, 2022 and 2025 builds listed as before their respective fixed builds; the vendor published updates that correct the vulnerable builds. Exploitation requires network access to the affected service and does not require valid credentials. The weakness is classified as CWE-416 (Use After Free).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows Server 2012 are affected?

BRANCHAFFECTEDFIXED
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349
Windows Server 2012 (Server Core installation) 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349
Windows Server 2012 R2 6.x6.3.9600.0 – before 6.3.9600.233986.3.9600.23398
Windows Server 2012 R2 (Server Core installation) 6.x6.3.9600.0 – before 6.3.9600.233986.3.9600.23398
Windows Server 2016 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows Server 2016 (Server Core installation) 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows Server 2019 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows Server 2019 (Server Core installation) 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows Server 2022 10.x10.0.20348.0 – before 10.0.20348.562210.0.20348.5622
Windows Server 2025 10.x10.0.26100.0 – before 10.0.26100.3343810.0.26100.33438

Is CVE-2026-78445 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-78445

  1. Apply Microsoft's security updates to reach the fixed builds (for example: 6.2.9200.26349 for Windows Server 2012/2012R2 branches and the corresponding fixed builds listed by Microsoft for 2016, 2019, 2022, 2025).
  2. If you cannot patch immediately, block or restrict network access to Services for NFS/ONCRPC traffic at the perimeter and internal firewalls.
  3. Monitor system and network logs for unexpected process creation or RPC activity and enable additional logging on NFS-related services.
  4. Follow Microsoft's guidance and deploy the vendor-supplied updates as soon as possible.

Frequently asked questions

Is CVE-2026-78445 being actively exploited?

There are no public reports of active exploitation of CVE-2026-78445 as of 2026-09-29.

Which Windows Server versions are affected by CVE-2026-78445?

Windows Server 2012 and 2012 R2, Windows Server 2016, 2019, 2022 and 2025 are affected in the build ranges listed by Microsoft; fixed builds are provided for each branch.

Is there a patch for CVE-2026-78445?

Yes. Microsoft published updates that fix the vulnerability; each affected branch has a specific fixed build number listed by the vendor.

Does CVE-2026-78445 require authentication?

No. The vulnerability can be exploited without authentication and only requires network access to the vulnerable Services for NFS component.

References