PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-26128 Microsoft CVE debrief

CVE-2026-26128 is a high-severity local privilege escalation vulnerability in Windows SMB Server, published 2026-03-10 and last modified 2026-05-26. The vulnerability stems from improper authentication (CWE-287) and allows an authorized attacker with local access to elevate privileges. The CVSS 3.1 score of 7.8 reflects high impact on confidentiality, integrity, and availability with low attack complexity. Affected products span multiple Windows client and server versions including Windows 10 (1607 through 22H2), Windows 11 (23H2 through 26H1), Windows Server 2012/R2, Windows Server 2016, 2019, 2022, 2022 23H2, and Windows Server 2025. Microsoft has issued a vendor advisory addressing this vulnerability. Third-party detection and mitigation scripts are also available. Organizations should prioritize patching based on the extensive affected product list and the high severity rating.

Vendor
Microsoft
Product
Windows 10 Version 1607
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-10
Original CVE updated
2026-05-26
Advisory published
2026-03-10
Advisory updated
2026-05-26

Who should care

System administrators managing Windows SMB Server deployments, security teams responsible for Windows patch management, and organizations with shared workstation or multi-user server environments where local privilege escalation poses significant risk.

Technical summary

Improper authentication in Windows SMB Server enables local privilege escalation. Attack vector is local with low complexity, requiring low privileges and no user interaction. Successful exploitation grants high impact across confidentiality, integrity, and availability. Affects broad Windows client and server portfolio with specific patch version boundaries identified per CPE criteria.

Defensive priority

high

Recommended defensive actions

  • Apply Microsoft security updates for affected Windows versions per the vendor advisory
  • Review and deploy available detection scripts to identify potential exploitation attempts
  • Implement available mitigation scripts as interim protection where patching is delayed
  • Prioritize patching on systems where local user accounts have elevated privileges
  • Monitor for anomalous privilege escalation activity on SMB Server endpoints

Evidence notes

CVE published 2026-03-10; modified 2026-05-26. CVSS 3.1 vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. Weakness: CWE-287 (Improper Authentication). Affected versions identified via NVD CPE criteria. Microsoft vendor advisory confirmed.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-26128 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-26128

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-26128 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-26128

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26128

    [email protected] - Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://www.vicarius.io/vsociety/posts/cve-2026-26128-detection-script-improper-authentication-in-windows-smb-server

    af854a3a-2127-422b-91ae-364da2661108

  • Source reference

    Unverified legacy reference

    URL: https://www.vicarius.io/vsociety/posts/cve-2026-26128-mitigation-script-improper-authentication-in-windows-smb-server

    af854a3a-2127-422b-91ae-364da2661108

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.