CVE-2026-56179: Windows Network Address Translation (NAT) Spoofing Vulnerability
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
Other sources
Windows Network Address Translation (NAT) Spoofing Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2704Patch KB5121000 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.33296Fixed in 10.0.26100.33222Patch KB5120228 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.9168Fixed in 10.0.26200.9106Patch KB5120994 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.9168Fixed in 10.0.26100.9106Patch KB5120994 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.9168Fixed in 10.0.26200.9106Patch KB5120994
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56179?
The severity of CVE-2026-56179 is classified as high with a score of 8.3.
How do I fix CVE-2026-56179?
To fix CVE-2026-56179, ensure that you apply the latest security updates provided by Microsoft for affected Windows versions.
What systems are affected by CVE-2026-56179?
CVE-2026-56179 affects Microsoft Windows 11, Microsoft Windows Server 2025, and specific releases of Windows 11 including 24h2, 25h2, and 26h1.
What kind of attack is possible due to CVE-2026-56179?
CVE-2026-56179 allows an unauthorized attacker to perform spoofing over an adjacent network due to an origin validation error in Windows Network Address Translation.
When was CVE-2026-56179 published?
CVE-2026-56179 was published on August 11, 2026.