CVE-2026-20833Patch(microsoft / windows_server_2008)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft windows_server_2008 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-327

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_server_2008
  • windows_server_2012
  • windows_server_2016
  • windows_server_2019

Threat summary

  • Patch or workaround signal is available
  • 19 mentions across 18 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 14 signals
  • Technical details provided in 9 signals
  • General: 5 classified signals
  • Peaked 4d ago at 2 mentions (2026-06-18); latest day: 1
  • 19 total mentions across 18 days

Affected systems

Vendors
Products
windows_server_2008windows_server_2012windows_server_2016windows_server_2019windows_server_2022windows_server_2022_23h2windows_server_2025

2 versions affected across 7 products

Deep dive

Activity timeline19 mentions / 18d
01122Mentions · 2026-01-27: 1Mentions · 2026-02-05: 1Mentions · 2026-02-08: 1Mentions · 2026-02-24: 1Mentions · 2026-03-11: 1Mentions · 2026-03-31: 1Mentions · 2026-04-02: 1Mentions · 2026-04-27: 1Mentions · 2026-05-11: 1Mentions · 2026-05-13: 1Mentions · 2026-05-15: 1Mentions · 2026-06-02: 1Mentions · 2026-06-16: 1Mentions · 2026-06-18: 2Mentions · 2026-06-22: 1Mentions · 2026-06-27: 1Mentions · 2026-07-01: 1Mentions · 2026-08-05: 1Patch / Workaround · 2026-01-27: 1Patch / Workaround · 2026-02-05: 1Patch / Workaround · 2026-02-08: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-13: 1Patch / Workaround · 2026-05-15: 1Patch / Workaround · 2026-06-16: 1Patch / Workaround · 2026-06-27: 1Patch / Workaround · 2026-07-01: 1Patch / Workaround · 2026-08-05: 1Technical Details · 2026-02-05: 1Technical Details · 2026-02-08: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-27: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-15: 1Technical Details · 2026-06-27: 1Technical Details · 2026-08-05: 101-2702-0502-0802-2403-1103-3104-0204-2705-1105-1305-1506-0206-1606-1806-2206-2707-0108-05
Signal classification2 categories
Patch
1473.7%
General
526.3%
Referenced assets14 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-271
Patch1
2026-02-051
Patch1
2026-02-081
Patch1
2026-02-241
General1
2026-03-111
Patch1
2026-03-311
Patch1
2026-04-021
Patch1
2026-04-271
Patch1
2026-05-111
Patch1
2026-05-131
Patch1
2026-05-151
Patch1
2026-06-021
General1
2026-06-161
Patch1
2026-06-182
General2
2026-06-221
General1
2026-06-271
Patch1
2026-07-011
Patch1
2026-08-051
Patch1
Full discourse19 posts
  • tamaiyutaro@tamai_pc
    General

    [告知] 7/1 (水曜日) に Active Directory 勉強会を開催します! テーマは、CVE-2026-20833 に伴う RC4 廃止についてです。 是非、皆さんのご参加をお待ちしておりますー https://configmgr.connpass.com/event/397482/ #ADIsNotDead #MECMJP

    Post summary

    An event announcement about a study session focusing on CVE-2026-20833 and RC4 deprecation, without technical details or exploitation information.

    0133411919.3K
    1.4K followersView on X
  • 🕳@sekurlsa_pw
    Patch

    So you might already have noticed kerberoast output changes since April, the enforcement phase with manual rollback. "The Windows updates released in or after July 2026 will remove support for the registry subkey RC4DefaultDisablementPhase." https://support.microsoft.com/en-us/topic/how-to-manage-kerberos-kdc-usage-of-rc4-for-service-account-ticket-issuance-changes-related-to-cve-2026-20833-1ebcda33-720a-4da8-93c1-b0496e1910dc#bkmk_timing_of_updates

    Post summary

    The post announces that updates released in or after July 2026 will remove support for a registry subkey linked to CVE‑2026‑20833, effectively patching the vulnerability.

    0301863.2K
    2.7K followersView on X
  • ぱっかーど@Packard197
    Patch

    Active Directory 勉強会 第8回 に参加中 CVE-2026-20833 に伴う RC4 廃止について http://configmgr.connpass.com/event/397482/ #ADIsNotDead #MECMJP

    Post summary

    The post announces an Active Directory study session and highlights that RC4 will be deprecated due to CVE‑2026‑20833, implying a mitigation but providing no technical or exploit details.

    00020113
    524 followersView on X
  • Silvio Di Benedetto@s_net
    Patch

    📢 #Article - RC4 deprecation in Kerberos: prepare for July 2026 enforcement 🔐 Kerberoasting & CVE-2026-20833 in Scope 🧩 msDS-SupportedEncryptionTypes Bitmask Decoded 🚫 Domain-Joined NAS & Legacy Devices Risk ⚙️ GPO and Per-Account Mitigation Strategies 📈 Audit, Remediate, Anticipate Before Enforcement 🔗 https://www.silviodibenedetto.com/rc4-deprecation-kerberos-active-directory-2026/ #DBS #MVPBuzz #ActiveDirectory #Kerberos #Security #Hardening #WindowsServer

    Post summary

    The article announces the upcoming RC4 deprecation in Kerberos, highlights CVE‑2026‑20833, outlines associated risks, and recommends GPO‑based mitigations to prepare before July 2026.

    00011118
    609 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Microsoft is forcing Kerberos RC4 out in three phases (Audit: January 2026, AES-Only Defaults: April 2026, Full Enforcement: July 2026). The underlying issue — CVE-2026-20833 — is that RC4 has quietly persisted as a fallback cipher in AD environments that believed they…

    Post summary

    Microsoft will phase out the RC4 Kerberos cipher in three stages to mitigate CVE‑2026‑20833, beginning with an audit in January 2026, then enforcing AES‑only defaults in April, and completing full enforcement by July 2026.

    1000035
    297 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    The attack surface story of 2026 can be told in one sentence: endpoints are the entry point; identity is the objective. Microsoft's three-phase Kerberos RC4 deprecation (CVE-2026-20833) reaches full enforcement in July 2026, after which any environment with legacy RC4…

    Post summary

    Microsoft will enforce Kerberos RC4 deprecation in July 2026, affecting environments still using legacy RC4.

    1000043
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    20833 reaches — The Identity Layer Is Your Last Line: An ITDR and Kerberos Hardening Playbook for 2026. Microsoft's three-phase Kerberos RC4 deprecation (CVE-2026-20833) reaches full enforcement in July 2026, after which any environment with legacy RC4 dependencies will…

    Post summary

    The post announces that Microsoft’s Kerberos RC4 deprecation (CVE‑2026‑20833) will reach full enforcement in July 2026, impacting environments with legacy RC4 dependencies.

    1000037
    294 followersView on X
  • なーの@narnos
    General

    Active Directory 勉強会 第 8 回目 https://configmgr.connpass.com/event/394218/ 今回は「CVE-2026-20833 に伴う RC4 廃止に向けた対応について考える回」だそうで弊社は対応済みのつもりだけど確認のために参加するぞ!

    Post summary

    The post announces a company’s participation in an AD meetup discussing CVE‑2026‑20833 and RC4 deprecation, but offers no technical, exploit, or patch details.

    0000163
    124 followersView on X
  • もくだいさん🇯🇵 365おじさん@mokudai
    Patch

    CVE-2026-20833 に関連するサービス アカウント チケット発行の変更に対する RC4 の Kerberos KDC 使用量を管理する方法 - Microsoft サポート https://support.microsoft.com/ja-jp/topic/cve-2026-20833-%E3%81%AB%E9%96%A2%E9%80%A3%E3%81%99%E3%82%8B%E3%82%B5%E3%83%BC%E3%83%93%E3%82%B9-%E3%82%A2%E3%82%AB%E3%82%A6%E3%83%B3%E3%83%88-%E3%83%81%E3%82%B1%E3%83%83%E3%83%88%E7%99%BA%E8%A1%8C%E3%81%AE%E5%A4%89%E6%9B%B4%E3%81%AB%E5%AF%BE%E3%81%99%E3%82%8B-rc4-%E3%81%AE-kerberos-kdc-%E4%BD%BF%E7%94%A8%E9%87%8F%E3%82%92%E7%AE%A1%E7%90%86%E3%81%99%E3%82%8B%E6%96%B9%E6%B3%95-1ebcda33-720a-4da8-93c1-b0496e1910dc#ID0EDDBN

    Post summary

    The Microsoft support article addresses CVE‑2026‑20833 by providing patch or workaround instructions and technical details, without indicating any PoC, exploit code, or active exploitation.

    10000211
    4.7K followersView on X
  • TexasTwerp@TexasTwerp
    General

    @techspence I’d rather read the entire MSFT post than give *that* site a click https://support.microsoft.com/en-us/topic/how-to-manage-kerberos-kdc-usage-of-rc4-for-service-account-ticket-issuance-changes-related-to-cve-2026-20833-1ebcda33-720a-4da8-93c1-b0496e1910dc

    Post summary

    The tweet merely points to a Microsoft support article about CVE‑2026‑20833, without providing additional details or evidence of exploitation.

    0001081
    203 followersView on X
  • SecEngCyGy@snypet86
    Patch

    July Windows updates finish Kerberos RC4 hard stop (CVE-2026-20833 path). Weak/RC4 tickets enable offline password recovery. Legacy paths break now. Audit RC4/legacy; fix service accounts around July hardening. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20833 #CyberSecurity

    Post summary

    The message announces Microsoft’s July patch that stops Kerberos RC4 support for CVE-2026-20833, notes that weak RC4 tickets allowed offline password recovery, and urges auditing of legacy tickets and service account fixes; no active exploitation or PoC is mentioned.

    0000041
    23 followersView on X
  • Doctor Kloud@doctorkloud
    Patch

    DES dans Kerberos disparaît. Microsoft fixe une date de suppression définitive et lie RC4 à CVE-2026-20833. Les filtres XML pour les événements 4768/4769 permettent de tracer les tickets DES (0x1, 0x2, 0x3) et RC4 (0x17) encore émis en production. L'Event Forwarding vers des canaux dédiés structure la détection à l'échelle. Attention : incompatible Server 2025 pour l'instant. https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/the-end-is-nigh-for-des-and-an-update-for-hunting-down-rc4/ba-p/4499821

    Post summary

    Microsoft is finalizing the removal of DES in Kerberos, linking remaining RC4 usage to CVE‑2026‑20833, and providing XML event filters to monitor relevant tickets while setting a definitive deprecation timeline.

    0000067
    24 followersView on X
  • Doctor Kloud@doctorkloud
    Patch

    RC4 Kerberos sur Azure Files : échéance avril 2026, les partages créés avant 2023 sont en première ligne. #CVE-2026-20833 Vérifiez via PowerShell si msDS-SupportedEncryptionTypes est nul sur vos objets AD liés au stockage. Migrez vers AES-256 avec AzFilesHybrid, purgez les tickets Kerberos cached, remontez les partages. Après juillet 2026, le rollback manuel disparaît. Pas de migration, pas d'accès SMB. https://techcommunity.microsoft.com/t5/azure-storage-blog/action-required-kerberos-rc4-hardening-may-affect-azure-files/ba-p/4518577

    Post summary

    The post warns that Azure Files will drop RC4 Kerberos support by April 2026 (CVE‑2026‑20833) and urges administrators to check msDS‑SupportedEncryptionTypes, migrate to AES‑256, purge Kerberos tickets, and remount shares as a mitigation.

    0000052
    23 followersView on X
  • Alberto "willoz" Troisi@uillo
    Patch

    🔐 Don't understimate the impact of the Windows patches related to Kerberos RC4 deprecation. Microsoft’s security hardening for Kerberos under CVE-2026-20833 is not “just another patch” https://www.linkedin.com/feed/update/urn:li:share:7459590150684160001/ #ActiveDirectory #Kerberos #WindowsServer #RC4 #AES #CVE202620833 https://t.co/IAOAf5YI8k

    Post summary

    The post highlights the importance of Microsoft’s Kerberos RC4 deprecation patch for CVE‑2026‑20833, stressing that it is more than a routine update, while offering no PoC, exploit, or technical details.

    0000025
    25 followersView on X
  • Xavier Rivera@SaviourProdigy
    Patch

    April's Windows cumulative update enforces AES-SHA1 over RC4 for Kerberos by default (CVE-2026-20833). If your FSLogix profile containers or NAS boxes rely on RC4 for SMB auth, profile loads will break at login. Audit your AD encryption types now — July kills the rollback.

    Post summary

    The April Windows cumulative update forces Kerberos to use AES-SHA1, breaking systems that rely on RC4 for SMB authentication; users should audit their AD encryption types before the July rollback.

    0000055
    243 followersView on X
  • Doctor Kloud@doctorkloud
    Patch

    Les certificats Secure Boot expirent en juin 2026. Vous avez quatre mois pour agir. Intune peut maintenant déployer ces certificats avec rapport de statut intégré. NTLM part à la retraite, Kerberos prend le relais. CVE-2026-20833 : première phase de correctifs disponible, auditez vos contrôleurs de domaine maintenant. WDS hands-free désactivé par défaut en avril 2026. Anticipez ou subissez. https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-news-you-can-use-january-2026/ba-p/4473282

    Post summary

    Microsoft highlights imminent Secure Boot certificate expiry, announces Intune certificate deployment capabilities, notes that the first patch phase for CVE‑2026‑20833 is available, and urges domain controller audits—no PoC, exploit, or active exploitation is reported.

    0000041
    13 followersView on X
  • マネージドエンジニア(志望)👻@iejirok
    Patch

    >最終的に 2026 年 7 月までに必要な対応を完了しなければ、一部の認証がブロックされます CVE‑2026‑20833 への対応とその影響について [KB5073381] https://jpwinsup.github.io/blog/2026/02/02/ActiveDirectory/Authentication/kerberos-rc4-for-service-account-ticket-issuance-changes-related-to-cve-2026-20833/

    Post summary

    The notice urges completion of required countermeasures by July 2026 to avoid authentication blocks, referencing a KB advisory that presumably contains the patch or mitigation for CVE‑2026‑20833.

    0000061
    311 followersView on X
  • Norio SASHIZAKI@sshzk
    Patch

    https://jpwinsup.github.io/blog/2026/02/02/ActiveDirectory/Authentication/kerberos-rc4-for-service-account-ticket-issuance-changes-related-to-cve-2026-20833/ CVE‑2026‑20833 への対応とその影響について [KB5073381] 最近話題になっている「CVE-2026-20833 に関連するサービス アカウント チケット発行の変更に対する RC4 の Kerberos KDC 使用量を管理する方法」に関する注意喚起です。

    Post summary

    The blog post announces Microsoft’s patch (KB5073381) for CVE‑2026‑20833, which addresses changes to RC4 usage in Kerberos KDC for service account ticket issuance and discusses its impact and mitigation.

    0000096
    419 followersView on X
  • WindowsForum@windowsforum
    Patch

    🔒 RC4 is being kicked out of Kerberos—Windows AD must migrate to AES via CVE-2026-20833. Inventory, remediate, upgrade, or risk a busted fallback. #WindowsForum #AD #Kerberos https://windowsforum.com/threads/rc4-deprecation-in-windows-kerberos-plan-aes-migration-for-ad.399164/?utm_source=rss&utm_medium=rss

    Post summary

    The message warns that RC4 is being removed from Kerberos because of CVE-2026-20833 and urges admins to inventory, remediate, or upgrade to AES to avoid fallback problems.

    0000054
    993 followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_server_2008--x64
OSmicrosoftwindows_server_2008--x86
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more