CVE-2026-26154Disclosure(microsoft / windows_server_2012)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch microsoft windows_server_2012 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_server_2012
  • windows_server_2016
  • windows_server_2019
  • windows_server_2022

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-14); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
windows_server_2012windows_server_2016windows_server_2019windows_server_2022windows_server_2022_23h2windows_server_2025

2 versions affected across 6 products

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-04-14: 2Mentions · 2026-04-17: 2Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-17: 204-1404-17
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-142
Disclosure1General1
2026-04-172
Disclosure2
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-26154 Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network. https://www.cve.org/CVERecord?id=CVE-2026-26154 ----- Traducción: CVE-2026-26154 Validación de entrada incorrecta en Windows … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-26154, describing an input validation flaw in Windows Server Update Service that enables unauthorized network tampering.

    0000061
    71 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26154 Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network. https://www.cve.org/CVERecord?id=CVE-2026-26154

    Post summary

    The brief notice announces CVE-2026-26154 as an input validation flaw in Windows Server Update Service that allows network tampering by an unauthorized attacker.

    00000267
    57.2K followersView on X
  • Red Hornet Intel@RedHornet_Intel
    Disclosure

    CVE-2026-26154 | Microsoft Windows Server 2012 | Vulnerability Description Unauth attacker exploits improper input validation in Windows Server Update Service (WSUS) over the network to tamper with updates, potentially enabling malicious update deployment. Severity: High Exploitation: Unknown Public PoC: Unknown Patch Available: Yes Affected Product: Microsoft Windows Server 2012 Affected Version: >= 6.2.9200.0 and < 6.2.9200.26026 Sources Vendor: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26154

    Post summary

    The entry announces CVE‑2026‑26154, detailing an authentication‑bypass vulnerability in WSUS that could allow tampering with updates, and confirms a patch is available. No PoC, exploit code, or active exploitation evidence is provided.

    0000070
    8 followersView on X
  • WindowsForum@windowsforum
    General

    🪟 WSUS tampering CVE—Microsoft “confidence signals” basically tell attackers how loud to knock. The scary part: patch speed + details decide who gets to play catch-up. https://windowsforum.com/threads/cve-2026-26154-wsus-tampering-why-microsoft-s-confidence-signals-matter.412654/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #CveSecurity #MicrosoftMsrc #WsusTampering #PatchInfrastructure https://t.co/uHfQweq1t6

    Post summary

    The post references the WSUS tampering CVE-2026-26154, noting Microsoft’s confidence signals and patch speed relevance, but it does not provide concrete technical, PoC, or exploitation details.

    0000026
    1.1K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more