Description
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
Published: 2026-08-11
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An origin validation error in the Windows Network Address Translation (NAT) component allows an attacker who is not authorized to spoof IP addresses on a network adjacent to the vulnerable host. Because the NAT layer fails to verify the source of packets properly, the attacker can inject traffic that appears to come from legitimate internal addresses. This flaw is classified as CWE‑346, reflecting insufficient input validation. An attacker who succeeds can forge traffic that may be accepted by downstream hosts, enabling man‑in‑the‑middle sessions, IP address spoofing, or potentially the execution of commands directed at internal systems.

Affected Systems

Microsoft Windows 11 build 24H2, 25H2, and 26H1, including both arm64 and x64 architectures, and Microsoft Windows Server 2025, including the standard and Server Core editions, are affected.

Risk and Exploitability

The CVSS score of 8.3 indicates a high severity vulnerability. The EPSS score of less than 1% suggests that active exploitation is currently unlikely, and the issue is not listed in the CISA KEV catalog. Inferred from the description, the likely attack vector is an adversary having network connectivity to the same subnet or VLAN as the target, either from a physically connected device or a compromised local host, and capable of sending crafted packets to the NAT service. The flaw requires no privileged local access, so it can be exploited remotely in the sense of being on the adjacent network, but it does not provide systemic escalation beyond the local network segment.

Generated by OpenCVE AI on August 12, 2026 at 15:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Windows update from Microsoft that addresses CVE-2026-56179.
  • Reboot the affected machines or restart the Windows Network Address Translation service to apply the fix.
  • Configure firewall or network ACLs to restrict inbound traffic from untrusted sources until the patch is applied.

Generated by OpenCVE AI on August 12, 2026 at 15:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows Server 2025 (server Core Installation)

Thu, 13 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
CPEs cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1

Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
Title Windows Network Address Translation (NAT) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-346
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:07:56.494Z

Reserved: 2026-06-19T13:53:31.990Z

Link: CVE-2026-56179

cve-icon Vulnrichment

Updated: 2026-08-13T13:44:14.647Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:04.363

Modified: 2026-08-13T14:17:01.747

Link: CVE-2026-56179

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T12:30:37Z

Weaknesses