Description
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
Published: 2026-07-14
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an origin‑validation error in Windows Network Address Translation (NAT). Because the NAT implementation does not sufficiently verify the source address of each packet, an attacker can forge the original source of traffic. This spoofing allows the attacker to elect virtual addresses that belong to legitimate hosts or services, thereby enabling the masquerade of legal traffic and potentially bypassing security controls that rely on accurate source identification.

Affected Systems

Microsoft Windows 11 version 24H2, 25H2, and 26H1, including ARM64 and x64 builds, and Microsoft Windows Server 2025 both in its full and Server Core installation modes are affected.

Risk and Exploitability

The CVSS score of 8.3 places the flaw in the high‑severity range, while the EPSS score of fewer than 1% indicates that large‑scale exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to be on the same local network or an adjacent network segment and to be able to send crafted packets that bypass NAT origin checks. The likely attack vector is local network traffic that can be redirected or spoofed by a malicious host in a nearby LAN or subnet.

Generated by OpenCVE AI on August 1, 2026 at 09:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the Microsoft Security Intelligence portal for any patches related to this vulnerability and apply them when released
  • Configure all network perimeter devices to enforce strict NAT origin validation, rejecting packets with spoofed source addresses
  • Segment affected machines from untrusted adjacent networks by implementing VLANs or isolated subnets to limit potential exploitation

Generated by OpenCVE AI on August 1, 2026 at 09:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
Title Windows Network Address Translation (NAT) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-346
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:27:54.855Z

Reserved: 2026-06-19T13:54:04.005Z

Link: CVE-2026-56181

cve-icon Vulnrichment

Updated: 2026-07-14T17:47:17.599Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:30:03Z

Weaknesses