CVE-2026-49179General(microsoft / windows_10_1607)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-11); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2012windows_server_2016

2 versions affected across 13 products

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-08-11: 2Mentions · 2026-09-21: 2Patch / Workaround · 2026-08-11: 108-1109-21
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets4 URLs
Full discourse4 posts
  • dbugs@ptdbugs

    A PoC/exploit has been discovered for vulnerability CVE-2026-49179 PT ID: PT-2026-70385 Vendor: Microsoft Product: Windows 10 Version 1607 Description: Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network. References: • https://dbu.gs/vulnerability/PT-2026-70385 • https://github.com/overgrowncarrot1/cve-2026-49179-active-directory-writespnscript-command-injection

    0301041.4K
    3.6K followersView on X
  • dbugs@ptdbugs

    A PoC/exploit has been discovered for vulnerability CVE-2026-49179 PT ID: PT-2026-70385 Vendor: Microsoft Product: Windows 10 Description: Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network. References: • https://dbu.gs/vulnerability/PT-2026-70385 • https://github.com/overgrowncarrot1/cve-2026-49179-active-directory-writespnscript-command-injection

    00073711
    3.6K followersView on X
  • Windows Forum@windowsforum
    Patch

    🚨 A remote-code flaw in Active Directory isn’t a “patch it when convenient” situation. Find every domain controller, apply August’s fix, and keep attackers out of the keys to the kingdom. https://windowsforum.com/security-alerts.84/cve-2026-49179-patch-windows-ad-ds-rce-on-domain-controllers.442489/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #WindowsServer #ActiveDirectory #SecurityUpdates #Cve202649179 https://t.co/IcDxpsgsWa

    Post summary

    The tweet highlights a remote‑code execution flaw in Active Directory and urges administrators to apply the August patch to secure domain controllers.

    0000046
    1.3K followersView on X
  • VulDB 🛡@vuldb
    General

    A new vulnerability with increased severity was disclosed for Microsoft Windows (CVE-2026-49179) https://vuldb.com/vuln/388272

    Post summary

    A new Windows CVE with an elevated severity rating was announced, but the post contains no additional technical details, PoC, exploit code, or mitigation information.

    0000097
    2.3K followersView on X
CPE platform detail24 entries

24 of 24 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2025--x64

Explore more