CVE-2026-56179Disclosure(microsoft / windows_11_24h2)

LOWCVSS 8.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft windows_11_24h2 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-346

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_11_24h2
  • windows_11_25h2
  • windows_11_26h1
  • windows_server_2025

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-11); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2025

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-11: 2Mentions · 2026-08-12: 1Patch / Workaround · 2026-08-11: 1Technical Details · 2026-08-11: 108-1108-12
Signal classification3 categories
Disclosure
133.3%
Patch
133.3%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-112
Disclosure1Patch1
2026-08-121
General1
Full discourse3 posts
  • Malcolm Stagg@malcolmst
    Patch

    Microsoft patched and published CVE-2026-56179 which relates to NatJack today, affecting Hyper-V in an upstream spoofing configuration. I have updated http://natjack.io with the CVE. Thank you @msftsecresponse for your work mitigating this! https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56179 #natjack

    Post summary

    Microsoft has released a patch for CVE-2026-56179, which impacts Hyper‑V’s NatJack component in an upstream spoofing scenario; the update is noted on Microsoft’s site and the NatJack website.

    01020191
    502 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos Microsoft ❗ CVE-2026-56179 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-microsoft-12/ https://t.co/pwbSoTwHbC

    Post summary

    The post references a Microsoft vulnerability (CVE‑2026‑56179) and links to a source for more information, but provides no further technical or exploit details.

    00000233
    6.7K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Microsoft Windows (CVE-2026-56179) https://vuldb.com/vuln/388273

    Post summary

    The post announces a severe Windows vulnerability (CVE‑2026‑56179) and directs readers to an external vulnerability database for additional details.

    00000119
    2.3K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2025--x64

Explore more