CVE-2026-0386
Microsoft · Published January 13, 2026
7.5
CVSS v3.1
HIGHPatch availableGet patch
Description
Windows Deployment Services Remote Code Execution Vulnerability. Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.
Affected Products
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
CVSS Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C