CVE-2026-0386Patch(microsoft / windows_server_2008)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft windows_server_2008 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_server_2008
  • windows_server_2012
  • windows_server_2016
  • windows_server_2019

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 7 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 3 mentions (2026-03-16); latest day: 1
  • 9 total mentions across 7 days

Affected systems

Vendors
Products
windows_server_2008windows_server_2012windows_server_2016windows_server_2019windows_server_2022windows_server_2022_23h2windows_server_2025

2 versions affected across 7 products

Deep dive

Activity timeline9 mentions / 7d
01223Mentions · 2026-02-01: 1Mentions · 2026-03-15: 1Mentions · 2026-03-16: 3Mentions · 2026-03-17: 1Mentions · 2026-03-25: 1Mentions · 2026-04-10: 1Mentions · 2026-04-18: 1Patch / Workaround · 2026-03-15: 1Patch / Workaround · 2026-03-16: 3Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-04-18: 1Technical Details · 2026-03-15: 1Technical Details · 2026-03-16: 3Technical Details · 2026-03-17: 1Technical Details · 2026-03-25: 1Technical Details · 2026-04-10: 102-0103-1503-1603-1703-2504-1004-18
Signal classification3 categories
Patch
555.6%
General
222.2%
Disclosure
222.2%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-011
General1
2026-03-151
Patch1
2026-03-163
Disclosure1Patch2
2026-03-171
Disclosure1
2026-03-251
General1
2026-04-101
Patch1
2026-04-181
Patch1
Full discourse9 posts
  • NeowinFeed@NeowinFeed
    Patch

    End of an era for legacy Windows deployments. 🛑 Microsoft is blocking hands-free WDS installations for Windows 11 and Server 2025 to patch a critical RCE vulnerability (CVE-2026-0386). Admins: Unattend.xml workflows are being phased out by April. Details: https://www.neowin.net/news/microsoft-blocking-a-windows-11--server-2025-automatic-installation-feature/

    Post summary

    Microsoft is blocking hands‑free WDS installations and phasing out Unattend.xml workflows as a patch to mitigate the severe RCE vulnerability CVE‑2026‑0386.

    623151276.2K
    29.6K followersView on X
  • tamaiyutaro@tamai_pc
    General

    ようやく検証できたので、ブログ記事にしました! Windows Deployment Services (WDS) に対するセキュリティ強化について (CVE-2026-0386) https://sccm.jp/2026/02/01/post-7545/ #WDS

    Post summary

    A blog post was posted about CVE-2026-0386, related to Windows Deployment Services, but the snippet offers no further technical details, exploitation evidence, or remediation information.

    0201151.3K
    1.4K followersView on X
  • Sohan Kanna@Sohan_Intel
    Disclosure

    Microsoft is killing “Hands-Free” OS deployment for Windows 11 & Server 2025. A critical RCE (CVE-2026-0386) in WDS lets attackers intercept credentials and inject payloads during PXE boot. Deep dive & mitigation: https://www.sohankanna.com/research/the-end-of-an-era-microsoft-kills-wds-hands-free-deployment-for-windows-11-server-2025-following-critical-rce #CyberSecurity #InfoSec #Windows https://t.co/1rgUeeeZkG

    Post summary

    Microsoft disclosed a critical RCE (CVE-2026-0386) in WDS that could allow attackers to intercept credentials and inject payloads during PXE boot, with a detailed deep dive and mitigation guidance linked.

    4001061
    1 followersView on X
  • Shea Lee@shealeeroy
    Patch

    April 2026 security update: Windows removes trust for deprecated cross-signed kernel drivers & disables WDS hands-free deployment by default (CVE-2026-0386). Patch your systems. #WindowsSecurity

    Post summary

    Windows has released a security update that removes trust for deprecated cross‑signed kernel drivers and disables WDS hands‑free deployment to mitigate CVE‑2026‑0386; systems should be patched.

    1000053
    19 followersView on X
  • Vicarius@vicariusltd
    General

    Nahuel and his team investigate deeply integrated vulnerabilities and reduce the attack surface with disabling, blocking, and other fun configurations. CVEs covered: CVE-2025-25017 Cross-Site Scripting in Kibana Vega Visualization Engine CVE-2026-0386 Remote Code Execution in Windows Deployment Services CVE-2026-24294 SMB Server Improper Authentication https://www.linkedin.com/pulse/issue-14-risk-ripples-outward-vicarius-g3qzc/

    Post summary

    The post simply enumerates several new CVEs, stating their affected components and vulnerability types, without any PoC, exploit, patch, or claim of active exploitation.

    00010209
    2.2K followersView on X
  • ThreatCluster@threatcluster
    Patch

    Microsoft will disable hands-free deployment in Windows Deployment Services due to critical RCE flaw CVE-2026-0386 that lets adjacent attackers intercept Unattend.xml to steal creds and run code. https://threatcluster.io/cluster/microsoft-to-disable-hands-free-deployment-due-to-critical-r-7cd46a63

    Post summary

    Microsoft is disabling hands‑free deployment in Windows Deployment Services to mitigate the critical CVE‑2026‑0386 RCE that allows attackers to intercept Unattend.xml for credential theft and code execution; no evidence of active exploitation, PoC, or false positive is presented.

    0001061
    101 followersView on X
  • J DS@jds_invoker
    Patch

    Something else? #MS_Windows #WDS Hands-Free Deployment Hardening Guidance related to #CVE-2026-0386 https://support.microsoft.com/en-us/topic/windows-deployment-services-wds-hands-free-deployment-hardening-guidance-related-to-cve-2026-0386-0daa3a3c-f3cd-4291-9147-a459c290c462

    Post summary

    Microsoft has released a hardening guidance article for CVE-2026-0386, providing mitigation steps but no PoC, exploit code, or evidence of active exploitation.

    0000056
    30 followersView on X
  • VaultEdge IT Solutions@VaultEdgeIT
    Disclosure

    🚨 Critical WDS Vulnerability Alert Microsoft will disable automated Windows deployments after a critical RCE flaw (CVE-2026-0386) that could let attackers intercept credentials during OS installations. 🔗 https://cybersecuritynews.com/windows-11-and-server-2025-automated-installation/ #Microsoft #WindowsServer #CyberSecurity #RCE https://t.co/eJswsFcsHL

    Post summary

    Microsoft reports a critical RCE flaw (CVE-2026-0386) that could let attackers intercept credentials during OS installations and plans to disable automated Windows deployments as a mitigation.

    0000055
    35 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Microsoft to Disable WDS Hands-Free Deployment After Critical RCE Flaw Microsoft will phase out hands-free deployment in Windows Deployment Services after CVE-2026-0386 exposed unattended installation files over an unauthenticated channel, creating a path for credential theft and remote code execution during PXE-based deployments. The issue matters because it turns a trusted enterprise provisioning workflow into a potential lateral-movement and deployment-poisoning vector if administrators do not harden or migrate affected setups. 🎯 Target: Global/Enterprise #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/windows-11-and-server-2025-automated-installation/

    Post summary

    Microsoft announced it will disable Windows Deployment Services hands‑free deployment due to CVE‑2026‑0386, a critical unauthenticated remote code execution flaw that could enable credential theft and lateral movement.

    0000057
    287 followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_server_2008--x64
OSmicrosoftwindows_server_2008--x86
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more