CVE-2026-26128PoC(microsoft / windows_10_1607)

MEDIUMCVSS 7.8 · HIGH

Exploit discussion active in current signal (8 latest mentions)

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 19 mentions across 7 observed days
  • Momentum state: rising

What's happening

  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 10 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 14 signals
  • Disclosure: 8 classified signals
  • General: 1 classified signal
  • Peaked at 8 mentions on most recent observed day (2026-07-22)
  • 19 total mentions across 7 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2012windows_server_2016

2 versions affected across 14 products

Deep dive

Activity timeline19 mentions / 7d
02468Mentions · 2026-03-16: 1Mentions · 2026-05-03: 1Mentions · 2026-06-15: 1Mentions · 2026-07-06: 5Mentions · 2026-07-07: 2Mentions · 2026-07-12: 1Mentions · 2026-07-22: 8PoC Mentioned / Linked · 2026-05-03: 1PoC Mentioned / Linked · 2026-06-15: 1PoC Mentioned / Linked · 2026-07-06: 4PoC Mentioned / Linked · 2026-07-07: 1PoC Mentioned / Linked · 2026-07-12: 1PoC Mentioned / Linked · 2026-07-22: 2Exploit Tool / Code · 2026-06-15: 1Exploit Tool / Code · 2026-07-06: 2Exploit Tool / Code · 2026-07-12: 1Exploit Tool / Code · 2026-07-22: 2Patch / Workaround · 2026-07-06: 1Patch / Workaround · 2026-07-22: 2Technical Details · 2026-03-16: 1Technical Details · 2026-06-15: 1Technical Details · 2026-07-06: 3Technical Details · 2026-07-07: 1Technical Details · 2026-07-22: 803-1605-0306-1507-0607-0707-1207-22
Signal classification3 categories
PoC
1052.6%
Disclosure
842.1%
General
15.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-161
Disclosure1
2026-05-031
PoC1
2026-06-151
PoC1
2026-07-065
Disclosure1PoC4
2026-07-072
General1PoC1
2026-07-121
PoC1
2026-07-228
Disclosure6PoC2
Full discourse19 posts
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-26128: Windows SMB Server Elevation of Privilege Vulnerability Critical Vulnerability Alert! kerberos is affected by CVE-2026-26128. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-26128 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-26128" Search Dork: service="kerberos" Exposure: 756.6k instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=c2VydmljZT0ia2VyYmVyb3Mi&t=all&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260706 #Infosec #CyberSecurity #ZoomEye #DarkEye

    Post summary

    The post announces CVE-2026-26128, an elevation of privilege flaw in Windows SMB Server affecting Kerberos, and provides links for further analysis and scanning.

    692044029638.9K
    12.7K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    Synacktiv publicly disclosed a Kerberos reflection bypass, CVE-2026-26128, with PoC exploit code. It yields SYSTEM on most Windows builds. Patch now. #Kerberos #PoC #CVE #Windows http://securityonline.info/kerberos-reflection-cve-2026-26128/

    Post summary

    Synacktiv disclosed CVE-2026-26128, a Kerberos reflection bypass affecting most Windows builds, with a PoC exploit and an available patch.

    04621458214.1K
    12.9K followersView on X
  • Mr. OS@ksg93rd
    PoC

    #Offensive_security Bypassing Windows (11 24H2/Server 2025) authentication reflection mitigations for SYSTEM shells Part 1 (CVE-2025-33073) https://www.synacktiv.com/en/publications/bypassing-windows-authentication-reflection-mitigations-for-system-shells-part-1 Part 2 (CVE-2026-26128) https://www.synacktiv.com/en/publications/bypassing-windows-authentication-reflection-mitigations-for-system-shells-part // Authentication relay (or reflection) attacks will persist as long as integrity mechanisms are not enforced by default on Windows services

    Post summary

    The tweet highlights the publication of proof‑of‑concept demonstrations for two Windows authentication reflection bypass CVEs, with no evidence of active exploitation or available patches.

    011053313.6K
    3.3K followersView on X
  • 🕳@sekurlsa_pw
    PoC

    (Note: this is from April) https://www.synacktiv.com/en/publications/bypassing-windows-authentication-reflection-mitigations-for-system-shells-part Reproduced by someone else: https://github.com/jarnovandenbrink/CVE-2026-26128

    Post summary

    The message points to a GitHub repository that reproduces CVE‑2026‑26128, offering a proof‑of‑concept, and cites a Synacktiv publication discussing the exploit.

    05019133.4K
    2.7K followersView on X
  • dbugs@ptdbugs
    PoC

    🔔 A PoC/exploit has been discovered for vulnerability CVE-2026-26128 PT ID: PT-2026-24331 Vendor: Microsoft Product: Windows 10 Version 1607 Description: Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. Link: https://github.com/jarnovandenbrink/CVE-2026-26128 #dbugs_vuln

    Post summary

    A public Proof of Concept exploit for CVE-2026-26128, enabling local privilege escalation via SMB authentication, has been released with a GitHub repository, but no active exploitation or patch information is mentioned.

    01052391
    3.0K followersView on X
  • Aircorridor@_aircorridor
    PoC

    Improper Authentication in Windows SMB Server by Microsoft | CVE-2026-26128 | Severity: HIGH PoC: https://github.com/jarnovandenbrink/CVE-2026-26128

    Post summary

    The tweet announces CVE-2026-26128, an authentication flaw in Windows SMB Server, and shares a PoC link, but does not provide exploitation or patch details.

    01022469
    13.2K followersView on X
  • キタきつね@foxbook
    PoC

    KerberosリフレクションバイパスCVE-2026-26128の概念実証(PoC)が公開される Kerberos Reflection Bypass CVE-2026-26128 Gets Public PoC Exploit #DailyCyberSecurity (Jul 6) https://securityonline.info/kerberos-reflection-cve-2026-26128/

    Post summary

    A proof of concept for Kerberos Reflection Bypass CVE-2026-26128 has been made public, but there is no evidence of active exploitation, patching, or detailed technical information in the text.

    00031407
    5.0K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Full Tweet 🚨 CVE-2026-26128: Windows SMB Server Elevation of Privilege Vulnerability 0day Intel: 🚨 CVE-2026-26128: Windows SMB Server Elevation of Privilege Vulnerability

    Post summary

    The tweet announces the discovery of CVE-2026-26128, a Windows SMB Server elevation‑of‑privilege vulnerability, but provides no PoC, exploit details, or patch information.

    1000041
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Source: X search for CVE-2026 critical Posted: 2026-07-06T06:36:44.000Z Likes: 169 0day Intel: 🚨 CVE-2026-26128: Windows SMB Server Elevation of Privilege Vulnerability

    Post summary

    The tweet announces the newly disclosed CVE‑2026‑26128, an elevation-of-privilege flaw in Windows SMB Server, with no PoC, exploit code, or patch details provided.

    1000044
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-26128: 🚨 CVE-2026-26128: Windows SMB Server Elevation of Privilege Vulnerability Critical Vulnerability Alert! kerberos is affected by CVE-2026-26128. Full Vulnerability Details & Analysis at DarkEye: 🔗 🔍 Identify Targets via…

    Post summary

    The text alerts readers to the new CVE-2026-26128, a Windows SMB Server elevation‑of‑privilege flaw affecting Kerberos, without providing PoC, exploit, patch details, or evidence of active exploitation.

    1000046
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    0day Intel: 🚨 CVE-2026-26128: Windows SMB Server Elevation of Privilege Vulnerability

    Post summary

    A brief alert announces the new CVE-2026-26128, noting it is a Windows SMB Server elevation of privilege vulnerability, without additional details or evidence of exploitation.

    1000041
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Source: X search for PoC exploit 2026 Posted: 2026-07-06T01:05:14.000Z Likes: 16 0day Intel: Synacktiv publicly disclosed a Kerberos reflection bypass, CVE-2026-26128, with

    Post summary

    Synacktiv announced a new Kerberos reflection bypass CVE-2026-26128, but no PoC, exploit or mitigation details were provided.

    1000065
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    Full Tweet Synacktiv publicly disclosed a Kerberos reflection bypass, CVE-2026-26128, with PoC exploit code. It yields SYSTEM on most Windows builds. Patch now. #Kerberos #PoC #CVE #Windows

    Post summary

    Synacktiv disclosed CVE-2026-26128, a Kerberos reflection bypass that can elevate to SYSTEM on most Windows builds, and shared PoC exploit code with a patch already available.

    1000067
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    CVE-2026-26128: Synacktiv publicly disclosed a Kerberos reflection bypass, CVE-2026-26128, with PoC exploit code. It yields SYSTEM on most Windows builds. Patch now. #Kerberos #PoC #CVE #Windows

    Post summary

    Synacktiv disclosed CVE‑2026‑26128, a Kerberos reflection bypass that allows SYSTEM privilege escalation on most Windows builds, shared PoC exploit code, and issued a patch.

    1000078
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    0day Intel: Synacktiv publicly disclosed a Kerberos reflection bypass, CVE-2026-26128, with

    Post summary

    Synacktiv has publicly disclosed CVE-2026-26128, a Kerberos reflection bypass vulnerability, with no additional details on PoC, exploitation, patching, or mitigations.

    1000048
    326 followersView on X
  • bfho@0xbfho
    General

    boh starred jarnovandenbrink/CVE-2026-26128 on Github https://ift.tt/om4KP2s

    Post summary

    The post merely indicates a GitHub star for a CVE repository, providing no additional information about the vulnerability.

    0000078
    513 followersView on X
  • Halil Deniz@denizhalilT
    PoC

    New public PoC exploit for CVE-2026-26128 targets Windows SMB/NTLM local reflection protections! Attackers can instantly escalate privileges to NT AUTHORITY\SYSTEM on Windows Server 2025/11. Read my full analysis: https://denizhalil.com/2026/07/07/cve-2026-26128-windows-smb-ntlm-bypass-analysis/ #CVE202626128 #Infosec #Cybersecurity https://t.co/RiW5hisvVO

    Post summary

    A public PoC exploit for CVE-2026-26128 demonstrates privilege escalation via SMB/NTLM local reflection protections on Windows Server 2025/11.

    0000088
    33 followersView on X
  • moton@moton
    PoC

    Kerberos Reflection LPE CVE-2026-26128 PoC Released - https://securityonline.info/kerberos-reflection-cve-2026-26128/

    Post summary

    A proof‑of‑concept for Kerberos Local Privilege Escalation CVE-2026-26128 is released and linked, but no exploit code, active exploitation, or patch information is included.

    00000120
    662 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26128 Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. https://www.cve.org/CVERecord?id=CVE-2026-26128

    Post summary

    A brief announcement of an authentication flaw in Windows SMB Server (CVE-2026-26128) that permits local privilege escalation, with a link to the CVE record but no further technical or exploitation details.

    00000195
    56.7K followersView on X
CPE platform detail25 entries

25 of 25 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025--x64

Explore more