CVE-2026-40415Disclosure(microsoft / windows_10_1809)

LOWCVSS 8.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft windows_10_1809 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2
  • windows_11_23h2

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-05-12); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2019windows_server_2022windows_server_2022_23h2

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-05-12: 3Mentions · 2026-05-15: 1Mentions · 2026-05-19: 1PoC Mentioned / Linked · 2026-05-19: 1Patch / Workaround · 2026-05-12: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-15: 1Technical Details · 2026-05-19: 105-1205-1505-19
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-123
Disclosure2General1
2026-05-151
General1
2026-05-191
Patch1
Full discourse5 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    General

    🚨تحديثات مايكروسوفت لشهر مايو 2026 قفلت مجموعه من الثغرات الخطيرة على المستخدمين العاديين و المنظمات ملخص الثغرات المهمه من وجهه نظري 📍CVE-2026-41089 في Windows Netlogon التقييم: 9.8 ثغرة RCE قبل المصادقة في Netlogon. خطورتها عالية جداً لأنها تسهل استهداف Domain Controllers، وقد تسمح بتنفيذ كود بصلاحيات عالية بدون حساب مسبق إذا توفرت شروط الاستغلال. هذي اهم ثغره ولازم تعطيها اولولية حالياً 📍CVE-2026-41096 في Windows DNS Client التقييم: 9.8 ثغرة Heap-based buffer overflow في dnsapi.dll. المهاجم قد يستغلها عبر استجابة لطلب DNS خبيث لتنفيذ كود عبر الشبكة. السيناريو الأخطر يظهر إذا قدر يتحكم في مسار DNS أو يستخدم DNS server خبيث أو هجمات Man-in-the-Middle 📍CVE-2026-42898 في Dynamics 365 On-Premises التقييم: 9.9 ثغرة RCE في Dynamics 365 On-Premises خلل في التحكم بعملية توليد الكود داخل Microsoft Dynamics 365 On-Premises يسمح لمهاجم مصادق بتنفيذ كود عبر الشبكة. 📍CVE-2026-40364 في Microsoft Word التقييم: 8.4 ثغرة RCE في Word. الخطر أنها قد تُستغل عند فتح أو معاينة ملف خبيث عبر Preview Pane في بعض السيناريوهات. انتبه ياصديقي لا تركز على نظام التشغيل فقط وتنسى Office. مرفق واحد قد يكون بداية الاختراق 📍CVE-2026-35439 وCVE-2026-40365 في SharePoint Server التقييم: 8.8 ثغرات RCE في SharePoint Server. SharePoint غالباً يحتوي ملفات داخلية، صلاحيات كبيرة ، وربط مع Active Directory. استغلاله قد يعطي المهاجم فرصة للوصول للشبكة الداخلية ويفتح باب للتنقل في الشبكه ايضا. 📍CVE-2026-40370 في SQL Server التقييم: 8.8 ثغرة RCE في SQL Server، لكنها تتطلب صلاحيات منخفضة. الخطر يرتفع إذا كان الخادم مكشوفاً على الانترنت أو إذا حصل المهاجم على حساب محدود. 📍CVE-2026-40415 في Windows TCP/IP التقييم: 8.1 ثغرة RCE في Network Stack نفسه. الخطورة أنها لا تعتمد على ملف Word أو Excel أو رابط تصيد. الاستغلال يتم من خلال الشبكة من خلال حزم مصممة بطريقة معينة. 📍CVE-2026-34332 في Windows Kernel-Mode Driver التقييم: 8.0 ثغرة RCE في Kernel-Mode Driver. عالية الخطورة لأنها مرتبطة طبقة حساسة من النظام. 📍CVE-2026-40359 في Excel التقييم: 7.8 ثغرة RCE في Excel. فتح أو معاينة ملف Excel خبيث قد يؤدي إلى تنفيذ كود على جهاز الضحية. هذا النوع من الثغرات مهم لأن ملفات Office ما زالت من أكثر أدوات الهجوم استخداماً داخل المؤسسات. 📍CVE-2026-34342 في Windows Print Spooler التقييم: 7.0 ثغرة Elevation of Privilege. ليست PrintNightmare جديدة، لكنها تذكرنا أن Print Spooler ما زال سطح هجوم مهم بعد الاختراق الأولي. إذا الخدمة غير مطلوبة على بعض الخوادم، عطّلها. وإذا مطلوبة، حدثها وراقب استخدامها

    Post summary

    The post catalogs several high‑severity Windows and Microsoft product CVEs, outlining their RCE nature and potential exploitation conditions, but it does not provide PoC, exploit code, patches, or evidence of active exploitation.

    03125912.7K
    50.0K followersView on X
  • VulDB 🛡@vuldb
    General

    Attention, elevated activities detected targeting Microsoft Windows (CVE-2026-40415) https://vuldb.com/vuln/363203/cti

    Post summary

    A short alert notes detected elevated activity targeting CVE-2026-40415 with a link to a vulnerability page, but offers no further technical or exploit details.

    0201098
    2.2K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Microsoft Windows (CVE-2026-40415) https://vuldb.com/vuln/363203

    Post summary

    A severe vulnerability (CVE-2026-40415) for Microsoft Windows was disclosed, with no further details or mitigations provided.

    02010126
    2.3K followersView on X
  • Alexander Leonov@leonov_av
    Patch

    🚨 May Microsoft Patch Tuesday: 119 vulns, 1 public exploit 🔥 EoP Windows Kernel (CVE-2026-40369); RCE DNS Client (CVE-2026-41096), Netlogon DC RCE (CVE-2026-41089), TCP/IP UAF (CVE-2026-40415) #PatchTuesday #Microsoft #Windows #AD #Vulristics ➡️ https://avleonov.com/2026/05/19/i055-may-microsoft-patch-tuesday/ https://t.co/mkRYGQkEvp

    Post summary

    The tweet announces Microsoft’s May Patch Tuesday release, lists 119 CVEs with brief technical categories, and notes one public exploit, but it does not provide exploit code or patch details.

    00000229
    1.0K followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🪟 CVE-2026-40415: Windows TCP/IP RCE is back, and the real twist is Microsoft saying “how confident are you with the details?” Translation: patch fast, then verify—don’t guess. #Windows #Security https://windowsforum.com/threads/cve-2026-40415-windows-tcp-ip-rce-patch-quickly-verify-confidence-limit-exposure.417852/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #WindowsSecurity #VulnerabilityManagement #PatchTuesday https://t.co/4OQ7Y0cPCo

    Post summary

    The message announces the CVE-2026-40415, describes it as a Windows TCP/IP Remote Code Execution issue, and urges timely patching, but offers no PoC, exploit details, or evidence of active exploitation.

    0000067
    1.1K followersView on X
CPE platform detail20 entries

20 of 20 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more