CVE-2026-33826Disclosure(microsoft / windows_server_2012)

HIGHCVSS 8.0 · HIGH

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch microsoft windows_server_2012 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.

6.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_server_2012
  • windows_server_2016
  • windows_server_2019
  • windows_server_2022

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 27 mentions across 9 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 22 signals
  • Disclosure: 10 classified signals
  • General: 6 classified signals
  • Peaked 7d ago at 7 mentions (2026-04-16); latest day: 1
  • 27 total mentions across 9 days

Affected systems

Vendors
Products
windows_server_2012windows_server_2016windows_server_2019windows_server_2022windows_server_2022_23h2windows_server_2025

1 version affected across 6 products

Deep dive

Activity timeline27 mentions / 9d
02457Mentions · 2026-04-15: 6Mentions · 2026-04-16: 7Mentions · 2026-04-17: 5Mentions · 2026-04-19: 2Mentions · 2026-04-20: 1Mentions · 2026-04-21: 2Mentions · 2026-04-22: 2Mentions · 2026-04-25: 1Mentions · 2026-05-03: 1PoC Mentioned / Linked · 2026-04-16: 1Active Exploitation · 2026-04-16: 1Active Exploitation · 2026-04-17: 1Patch / Workaround · 2026-04-16: 4Patch / Workaround · 2026-04-17: 2Patch / Workaround · 2026-04-21: 2Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-15: 3Technical Details · 2026-04-16: 7Technical Details · 2026-04-17: 4Technical Details · 2026-04-19: 2Technical Details · 2026-04-21: 2Technical Details · 2026-04-22: 2Technical Details · 2026-04-25: 1Technical Details · 2026-05-03: 104-1504-1604-1704-1904-2004-2104-2204-2505-03
Signal classification5 categories
Disclosure
1037.0%
Patch
933.3%
General
622.2%
PoC
13.7%
Active Exploitation
13.7%
Referenced assets24 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-156
Disclosure3General3
2026-04-167
Disclosure2Patch4PoC1
2026-04-175
Active Exploitation1Disclosure1General1Patch2
2026-04-192
Disclosure2
2026-04-201
General1
2026-04-212
Patch2
2026-04-222
General1Patch1
2026-04-251
Disclosure1
2026-05-031
Disclosure1
Full discourse20 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    🚨 ثغرة بتقييم 8.0 في Windows Active Directory. رقم الثغرة: CVE-2026-33826. ⚠️ يستطيع أي مستخدم عادي في الدومين استغلال الثغرة. الكود الخبيث يُنفذ بنفس صلاحيات خدمة RPC المخترقة، والتي تعني غالبا السيطرة على الـ DC. التفاصيل : 🧵👇

    Post summary

    A new CVE‑2026‑33826 vulnerability in Windows Active Directory is disclosed, rated at CVSS 8.0, with the text noting that any domain user could exploit the RPC service, but no PoC, exploit tool, or patch is provided.

    291745335.5K
    49.3K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    General

    🪟 بيئة أنظمة Microsoft: (هذه الثغرات رغم ان تصنيفها بين High 8.0-8.7، تأثيرها التشغيلي خطير جداً) 🗄️ خدمة Active Directory: ⚠️ الخطر: تنفيذ أوامر عن بُعد (RCE) برقم (CVE-2026-33826). 🔐 بروتوكول Windows Kerberos: ⚠️ الخطر: تصعيد للصلاحيات برقم (CVE-2026-27912). 👋 ميزة Windows Hello: ⚠️ الخطر: تجاوز آلية المصادقة في Windows Hello برقم (CVE-2026-27928).

    Post summary

    The text lists three high‑severity CVEs affecting Microsoft Windows components—Active Directory RCE, Kerberos privilege escalation, and Windows Hello authentication bypass—without providing any PoC, exploit details, or mitigation information.

    000451.6K
    49.3K followersView on X
  • アイティーサポート株式会社【採用】@its_recruit_x
    Disclosure

    スタッフブログを更新しました 【緊急】Windows Active Directory の RCE 脆弱性「CVE-2026-33826」に注意 | アイティーサポート株式会社 https://itsupport-inc.com/news/969/

    Post summary

    The blog post issues an urgent warning about the CVE-2026-33826 RCE vulnerability in Windows Active Directory, but provides no PoC, exploit code, or patch information.

    01030165
    14 followersView on X
  • 𝕏 Bug Bounty Writeups 𝕏@bountywriteups
    Disclosure

    Windows Active Directory Flaw Enables Remote Code Execution (CVE-2026-33826) https://medium.com/@ajudeb55/windows-active-directory-flaw-enables-remote-code-execution-cve-2026-33826-04968705df96?source=rss------bug_bounty-5 #bugbounty #bugbountytips #bugbountytip

    Post summary

    The Medium article announces CVE-2026-33826, a Windows Active Directory flaw that enables remote code execution, but it provides no PoC, exploit, or patch details.

    00021622
    40.1K followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    📅 April CVE‑treasure: CVE‑2026‑33826. Windows AD improper‑input‑validation bug lets an authenticated attacker on the same AD‑segment execute code over an adjacent network via crafted RPC. Domain‑controllers and AD‑linked services need this patch ASAP. #CVE2026‑33826 #ActiveDirectory #RCE https://www.cve.org/CVERecord?id=CVE-2026-33826

    Post summary

    The post announces a Windows AD RCE vulnerability (CVE-2026-33826) that permits authenticated attackers to execute code via custom RPC and urges immediate patching of domain controllers and related services.

    1001050
    1.0K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-33829 2 - CVE-2026-33826 3 - CVE-2026-39813 4 - CVE-2026-30898 5 - CVE-2026-4631 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    A simple listing of the top five trending CVEs with no additional vulnerability details, patches, or exploitation information.

    00011172
    1.7K followersView on X
  • RB@RynBsd
    Disclosure

    CVE-2026-33826 في Active Directory: RCE بامتيازات مضيف RPC عبر اتصالات داخلية https://t.co/b9YKBPewbu

    Post summary

    The tweet announces CVE-2026-33826 as an Active Directory Remote Code Execution that escalates to host privileges via internal RPC, but it provides no proof‑of‑concept, exploit code, patch, or evidence of active exploitation.

    0001063
    8 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Active Directory の脆弱性 CVE-2026-33826 が FIX:隣接ネットワーク経由での RCE https://iototsecnews.jp/2026/04/15/windows-active-directory-flaw-opens-door-to-malicious-code-execution/ この脆弱性の原因は、Windows Active Directory の中核となるシステムにおいて、外部からのデータ通信を受け取る際のチェック機能 (入力検証) の不備にあります。具体的には、ネットワーク経由でプログラムを遠隔操作する仕組みである、RPC (リモートプロシージャコール) の処理過程に、この脆弱性が存在します。ドメイン内の基本的なユーザー権限さえ持っている攻撃者であれば、特別に細工した RPC リクエストを送信するだけで、サーバ上で任意のプログラムを実行させることが可能になります。すでに、2026年04月の Patch Tuesday で修正されていますので、ご確認ください。 #ActiveDirectory #CVE202633826 #Microsoft #Vulnerability

    Post summary

    A RCE flaw (CVE-2026-33826) in Windows Active Directory via RPC was fixed in April 2026 Patch Tuesday; no PoC, active exploitation, or exploit code is mentioned.

    01000145
    486 followersView on X
  • Alexei Belous@AlexeiBelous
    Patch

    CVE-2026-33826 is “authenticated + adjacent network” AD RPC RCE. Don’t downgrade it. Attackers only need *any* domain cred, then they look for code exec near the identity plane (DC / mgmt / automation). Patch AD-adjacent hosts first. “Auth required” = “already inside”.

    Post summary

    CVE-2026-33826 is an authenticated RPC Remote Code Execution in Active Directory that requires any domain credentials and can be mitigated by patching AD‑adjacent hosts.

    0001063
    7 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    PoC

    🚨 #CVE-2026-33826: The 80-Second RCE That Turns Your Identity Management Into a Sieve + Video https://undercodetesting.com/cve-2026-33826-the-80-second-rce-that-turns-your-identity-management-into-a-sieve-video/ Educational Purposes!

    Post summary

    The post shares a video demo of an 80‑second remote code execution flaw in an identity management system, offering a proof‑of‑concept without evidence of active exploitation, patches, or debunking.

    0001070
    491 followersView on X
  • Alexei Belous@AlexeiBelous
    Patch

    “Authenticated attacker in the same domain” is not a comforting prerequisite. April Patch Tuesday had an AD RPC RCE (CVE-2026-33826): once a foothold exists, AD can become the execution boundary. Patch fast; otherwise lock down DC RPC reachability + segment + monitor RPC.

    Post summary

    The post highlights the CVE‑2026‑33826 AD RPC remote code execution vulnerability, stresses the need to apply the patch immediately, and recommends RPC isolation and monitoring.

    0001054
    7 followersView on X
  • Café et tech ☕@cafe_et_build
    Disclosure

    4/ Bonus cauchemar : CVE-2026-33826 (Active Directory) Exécution de code dans le domaine avec une authentification simple. Active Directory compromis = contrôle total du domaine. Scénario de fin du monde pour tout admin sys.

    Post summary

    The tweet announces CVE‑2026‑33826 as a Remote Code Execution flaw in Active Directory that can be exploited with simple authentication, but it offers no proof of exploitation, patches, or PoC.

    10000105
    82 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33826 Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network. https://www.cve.org/CVERecord?id=CVE-2026-33826

    Post summary

    The post briefly mentions CVE-2026-33826 as an input validation flaw in Windows AD that could allow code execution over an adjacent network, but offers no further technical, patch, or exploit details.

    000101.1K
    57.2K followersView on X
  • Patel Mahendra@Mahendrak29
    General

    https://whatsapp.com/channel/0029VbAre6eKQuJNLsryuQ0u/112 🔴 Zero-Day CVE-2026-32201 – SharePoint Spoofing CVE-2026-33825 – Publicly Disclosed 🔴 Critical: CVE-2026-33827 – Windows RCE CVE-2026-33826 – Active Directory RCE CVE-2026-32157 – RDP Client RCE CVE-2026-32190 – Microsoft Office RCE #cyber

    Post summary

    The message lists several CVE identifiers with minimal descriptors but provides no further technical or operational details.

    00010239
    1 followersView on X
  • kawn@kawn2020
    General

    #windowsupdate #microsoft つづき ・CVE-2026-32225 8.8 Windows シェル ・CVE-2026-33825 7.8 Microsoft Defender ・CVE-2026-33826 8  Windows Active Directory -対象外:1 件 ・CVE-2026-33118 4.3 Microsoft Edge (Chromium ベース)

    Post summary

    The post lists several 2026 CVEs with their CVSS scores and affected Microsoft products, but provides no evidence of PoC, exploitation, patches, or technical exploitation details.

    10000196
    85 followersView on X
  • Ergun Akman@AturcDestek
    Disclosure

    🚨 Windows Active Directory'de Kritik Uzaktan Kod Çalıştırma Zafiyeti (CVE-2026-33826) https://www.linkedin.com/pulse/windows-active-directoryde-kritik-uzaktan-kod-%25C3%25A7al%25C4%25B1%25C5%259Ft%25C4%25B1rma-ergun-akman-bbw8f @LinkedIn aracılığıyla

    Post summary

    The post announces a critical remote code execution vulnerability (CVE‑2026‑33826) in Windows Active Directory and links to a LinkedIn article, but provides no PoC, exploit details, or patch information.

    0000031
    18 followersView on X
  • Alexei Belous@AlexeiBelous
    General

    CVE-2026-33826 (AD RPC RCE) is the classic “needs auth + adjacent network” trap. In a real enterprise, “adjacent” = any domain user on the LAN. If a phished credential can reach RPC on a DC, you’ve turned a foothold into a domain incident.

    Post summary

    The post discusses the nature of CVE‑2026‑33826 as an AD RPC remote code execution that requires authentication and adjacent users, but offers no evidence of exploitation tools, PoC, or active attacks.

    0000050
    7 followersView on X
  • CinchOps@CinchOpsIT
    Patch

    ⚠️ 𝗪𝗶𝗻𝗱𝗼𝘄𝘀 𝗔𝗰𝘁𝗶𝘃𝗲 𝗗𝗶𝗿𝗲𝗰𝘁𝗼𝗿𝘆 𝗛𝗮𝘀 𝗮 𝗖𝗿𝗶𝘁𝗶𝗰𝗮𝗹 𝗙𝗹𝗮𝘄 - 𝗣𝗮𝘁𝗰𝗵 𝗡𝗼𝘄 CVE-2026-33826: Critical Windows Active Directory flaw lets attackers execute code on your server. CVSS 8.0. Affects Windows Server 2012 R2 through 2025. AD is the spine of most business networks - if it falls, everything behind it is exposed. Patches are out. Apply them. ❓Does your patch management process catch critical fixes within 24 hours? 📲 CinchOps handles that for Houston businesses. 🌐 http://cinchops.com/contact | 📲 281‑269‑6506 Full Article: https://cybersecuritynews.com/windows-active-directory-vulnerability/ #ITSupport #cybersecurity #HoustonSMB #PatchManagement #WindowsServer

    Post summary

    CVE-2026-33826 is a critical Windows Active Directory flaw permitting remote code execution; patches are available and are being urged for immediate deployment.

    0000056
    3 followersView on X
  • Alexander Leonov@leonov_av
    Active Exploitation

    🚨 April MS Patch Tuesday: 167 vulns - 🟠 exploited SharePoint (CVE-2026-32201), ⚠️ likely exploit EoP Defender (CVE-2026-33825), 💥 RCE AD (CVE-2026-33826), wormable IKE (CVE-2026-33824) & TCP/IP (CVE-2026-33827) #PatchTuesday #Microsoft #Windows ➡️ https://t.me/avleonovcom/1643 https://t.co/GjaBjY68Oa

    Post summary

    The tweet reports that certain 2026 Microsoft vulnerabilities are being actively exploited, highlighting SharePoint, Defender, AD, IKE, and TCP/IP issues, but provides no patch or technical detail.

    00000198
    1.0K followersView on X
  • CyberTech Insights@CyberTech_In
    Patch

    Microsoft warns of a critical flaw in Windows Active Directory (CVE-2026-33826) Enables remote code execution within enterprise networks. Patch ASAP. 𝐑𝐞𝐚𝐝 𝐅𝐮𝐥𝐥 𝐒𝐭𝐨𝐫𝐲 : https://cybertechnologyinsights.com/ai-security/microsoft-active-directory-flaw-enables-remote-code-execution/ https://t.co/3KOvnuqLxX

    Post summary

    Microsoft has announced a critical RCE vulnerability in Windows Active Directory (CVE-2026-33826) and urges organizations to patch immediately; no PoC, exploit, or evidence of active exploitation is mentioned.

    0000080
    17 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more