CVE-2026-62893Patch(microsoft / windows_10_1607)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_server_2012
  • windows_server_2016

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Peaked 4d ago at 3 mentions (2026-08-12); latest day: 1
  • 8 total mentions across 6 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_server_2012windows_server_2016windows_server_2019windows_server_2022windows_server_2025

2 versions affected across 7 products

Deep dive

Activity timeline8 mentions / 6d
01223Mentions · 2026-08-11: 1Mentions · 2026-08-12: 3Mentions · 2026-08-14: 1Mentions · 2026-08-19: 1Mentions · 2026-08-24: 1Mentions · 2026-09-09: 1Active Exploitation · 2026-08-12: 2Patch / Workaround · 2026-08-11: 1Patch / Workaround · 2026-08-12: 1Patch / Workaround · 2026-08-14: 1Patch / Workaround · 2026-08-24: 1Technical Details · 2026-08-11: 1Technical Details · 2026-08-12: 2Technical Details · 2026-08-14: 1Technical Details · 2026-08-24: 1Technical Details · 2026-09-09: 108-1108-1208-1408-1908-2409-09
Signal classification3 categories
Patch
337.5%
Disclosure
337.5%
Active Exploitation
225.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-08-111
Patch1
2026-08-123
Active Exploitation2Disclosure1
2026-08-141
Patch1
2026-08-191
Disclosure1
2026-08-241
Patch1
2026-09-091
Disclosure1
Full discourse8 posts
  • National CERT/CC@CERT_UG
    Patch

    🚨 Patch Now | August 24, 2026 Bringing these CVEs to your attention! - Windows TFTP Server (CVE-2026-62893, CVSS 9.8 - SharePoint (CVE-2026-63520, CVSS 9.1) - Citrix NetScaler (CVE-2026-19490, CVSS 9.3): http://cert.ug | #CyberSafeUG #CERTUGCC https://t.co/pZmfJBv2yz

    Post summary

    A concise advisory urging users to patch three high‑severity Windows TFTP Server, SharePoint, and Citrix NetScaler vulnerabilities, providing CVSS scores and a link for further information.

    03160352
    1.5K followersView on X
  • kawn@kawn2020
    Disclosure

    #windowsupdate #microsoft つづき ・CVE-2026-62878 Windows DNS サーバーのリモートでコードが実行される脆弱性 ・CVE-2026-62893 Windows 展開サービス TFTP Server のリモートでコードが実行される脆弱性 ・CVE-2026-65789 Windows DNS サーバーのリモートでコードが実行される脆弱性

    Post summary

    The tweet announces three new Microsoft Windows DNS/TFTP Server CVEs that allow remote code execution, but provides no PoC, exploit, patch, or evidence of active exploitation.

    1001099
    87 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🪟 Use-after-free in Windows Deployment Services TFTP Server = unauthenticated RCE over the network. CVE-2026-62893 hits CVSS 9.8 across Win10, Server 2012-2025. Patch is out. Apply it. #cybersecurity #ciso #cto #vulnerabilities #mssp https://secalerts.co/vulnerability/CVE-2026-62893?utm_campaign=x https://t.co/yvKyxwPidv

    Post summary

    The post highlights a critical UAF vulnerability in Windows Deployment Services with an available patch and urges immediate update, without providing exploit code or evidence of active attacks.

    01010265
    879 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    【緊急】CVE-2026-62893 マイクロソフトのMicrosoft Windows 10 1607に深刻な脆弱性|即時対応が必要 https://www.cybernote.click/2026/08/17/cve-2026-62893-microsoft-windows-10-1607/ #IT #Security #cybersecurity

    Post summary

    The message alerts readers to a critical vulnerability (CVE-2026-62893) affecting Microsoft Windows 10 1607, emphasizing the need for immediate action but provides no further technical or remedial details.

    0001049
    209 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Microsoft Windows (CVE-2026-62893) https://vuldb.com/vuln/388612

    Post summary

    A new Windows vulnerability (CVE‑2026‑62893) has been disclosed with a higher severity score, but the snippet offers no PoC, exploit details, or mitigation information.

    00010123
    2.3K followersView on X
  • VulniPulse@vulnipulse
    Patch

    🚨 CRITICAL CVE ALERT CVE-2026-62893 · Microsoft Windows Server 2019 · CVSS 9.8 Attackers could execute arbitrary code. Upgrade to a vendor-listed fixed release. 🔎 Full advisory: https://vulnipulse.com/advisories/microsoft-cve-2026-62893 #CyberSecurity #CVE #Microsoft #WindowsServer

    Post summary

    The advisory highlights CVE‑2026‑62893 as a critical flaw in Windows Server 2019, noting its ability to allow arbitrary code execution and a CVSS score of 9.8, and recommends upgrading to a vendor‑released patch.

    1000042
    7 followersView on X
  • ThreatAft@ThreatAft
    Active Exploitation

    🚨 Microsoft August Patch Tuesday — 398+ CVEs, 3 Zero-Days CVE-2026-68820 — WinSock EoP (ACTIVE zero-day, Lazarus) CVE-2026-62878 — DNS Server RCE (9.8, wormable) CVE-2026-62893 — TFTP Server RCE (9.8, more likely) → http://threataft.com/articles/microsoft-august-2026-patch-tuesday-398-cves #cybersecurity #PatchTuesday #ZeroDay

    Post summary

    The article announces Microsoft’s August Patch Tuesday featuring 398+ CVEs and highlights three zero‑days, including an actively exploited WinSock EoP (claimed by Lazarus) and two high‑score RCE vulnerabilities.

    00000115
    36 followersView on X
  • OJOBIT@0J0BIT
    Active Exploitation

    August Patch Tuesday ships 421 fixes, 62 critical, and one actively exploited CVE: CVE-2026-68820 in Windows AFD.sys > August's Patch Tuesday hits 421 CVEs, including 62 critical flaws and an actively exploited Windows AFD use-after-free, with Talos Snort rules ready > microsoft's critical bucket holds 40 RCEs, led by Windows Deployment Services, DHCP Server, SharePoint, and DNS Server > August Patch Tuesday ships fixes for 421 CVEs, 62 of them marked critical, and one of them is already being exploited: CVE-2026-68820, a use-after-free in the Windows > remote code execution dominates the critical bucket: 40 of the 62 critical vulnerabilities are RCEs > CVSS puts it at 7.0, which reads as mid-tier, but an in-the-wild label changes the ordering of your patch queue > Windows Deployment Services TFTP Server's CVE-2026-62893 (CVSS 9.8) is a use-after-free an unauthorized attacker can hit over a network; Windows DHCP Server's https://news.ojobit.com/story/microsoft-august-2026-patch-tuesday-421-cves-2e8434

    Post summary

    The note highlights that CVE-2026-68820, a use‑after‑free in Windows AFD.sys, is actively exploited in the wild, underscoring the urgency of the August Patch Tuesday release.

    0000049
    12 followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2025--x64

Explore more