CVE-2026-62818
Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
Description
Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.
In plain language
AI Act nowCVE-2026-62818 is a Windows AD CS flaw that can let an attacker with a low-level account run code on the certificate server over the network; if you run AD CS, you should act now, especially if attackers might get any account.
CVE-2026-62818 is a remote code execution issue in Windows Active Directory Certificate Services (AD CS) where a low-privileged, authenticated attacker can trigger a memory safety flaw (use-after-free) with no user interaction to execute unauthorized code on the server.
What to do now
- Check whether your environment runs Windows Active Directory Certificate Services (AD CS) on any of: windows 10, windows server 2012, windows server 2012 r2, windows server 2016, windows server 2019, windows server 2022, windows server 2025.
- Confirm whether the affected server is reachable over the network by users/accounts that an attacker could potentially obtain (the weakness requires an authorized account).
- Upgrade/patch immediately to the fixed versions listed by Microsoft for CVE-2026-62818 on each operating system you run.
- After patching, review AD CS-related event logs and authentication activity for unusual attempts shortly before and after the update deployment.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62818 and every CVE in our database. Create a free account — no credit card required.
Create Free Account