CVE-2026-62893
Windows Deployment Services TFTP Server Remote Code Execution Vulnerability
Description
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
In plain language
AI Act nowThis is a Windows networking bug in the Windows Deployment Services TFTP server that can let a remote attacker run malicious code without you clicking anything; if you run Windows Deployment Services, you should treat it as urgent to patch.
CVE-2026-62893 is a remote code execution vulnerability caused by a use-after-free bug in the Windows Deployment Services (WDS) TFTP server; attackers can trigger it over the network without authentication or user interaction, leading to full compromise of the affected Windows machine.
What to do now
- Check whether your business uses Windows Deployment Services (WDS) and whether its TFTP service is reachable from other networks (especially the internet or untrusted networks).
- Identify your exact Windows version/build number for each affected machine (Windows 10, Windows Server 2012/2012 R2/2016/2019/2022/2025).
- Apply the vendor fixes for your OS branch: Windows 10 (10.0.14393.9418 and/or 10.0.17763.9115 and/or 10.0.17763.9121), Windows Server 2012 (6.2.9200.26280), Windows Server 2012 R2 (6.3.9600.23338), Windows Server 2016 (10.0.14393.9418), Windows Server 2019 (10.0.17763.9115 and/or 10.0.17763.9121), Windows Server 2022 (10.0.20348.5440 and/or 10.0.20348.5499), Windows Server 2025 (10.0.26100.33222 and/or 10.0.26100.33296).
- If patching takes time, restrict network access so the WDS TFTP server is not reachable from untrusted networks until updated.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft выпустила патчи более чем для 400 уязвимостейru-ru·Хакер (xakep.ru)· Exploited Windows Lazarus
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attacken·The Hacker News· Exploited Windows Lazarus Group
- August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Dayen-us·SecurityWeek· Exploited Windows Lazarus group
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62893 and every CVE in our database. Create a free account — no credit card required.
Create Free Account