CyberICT

CVE-2026-0386

Microsoft · Published January 13, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Windows Deployment Services Remote Code Execution Vulnerability. Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.

Affected Products

  • Windows Server 2019
  • Windows Server 2019 (Server Core installation)
  • Windows Server 2022
  • Windows Server 2022 (Server Core installation)

CVSS Vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C