a 9.8 in a Windows Server network driver lets an attacker run code with nothing but network traffic

CVE-2026-56188 is a race condition in a core Windows Server network driver that an unauthenticated attacker can exploit remotely. It affects every…

Aliteq
Priya Nair · Software & Systems Editor

What you need to know

The flaw: a race condition (CWE-362) in a Windows Server network driver → unauthenticated remote code execution.

What you need to know

Scores: Microsoft 9.8, NIST 8.1 — the difference is attack complexity (NIST rates it higher-complexity).

What you need to know

Affected: Windows Server 2012 through 2025, plus Windows 10 and 11 (x64, 32-bit, ARM64).

What you need to know

No auth, no user interaction — reachable over the network, in a kernel-level driver.

What you need to know

Fix: the July 2026 security update. Prioritise internet-facing and critical servers.

Aliteq

Read the full story

a 9.8 in a Windows Server network driver lets an attacker run code with nothing but network traffic

Read the full story on Aliteq