Impact
The CVE-2026-62759 vulnerability involves an authentication bypass in the Windows Netlogon protocol. An attacker able to spoof Netlogon messages over an adjacent network can trick a Windows client or server into authenticating as a legitimate domain controller or user. This flaw is categorized as CWE‑290 and can lead to unauthorized access or lateral movement within a domain.
Affected Systems
Affected systems are Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both full and Server Core installations.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high severity. The EPSS score is not available, and the CVE is not listed in the CISA KEV catalog. The vulnerability requires an attacker to be on the same local network or otherwise able to inject spoofed Netlogon traffic. Once exploited, the attacker can obtain valid authentication to the domain, potentially leading to privilege escalation or lateral movement. No public exploits have been confirmed, but the lack of a KEV listing does not negate the need for mitigation.
OpenCVE Enrichment