CVE-2026-62818: Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
Published Aug 11, 2026
·Updated
Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.
Other sources
Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
— Microsoft
Affected Software
26 affected componentsFixes available
Microsoft Windows Server 2016<10.0.14393.9418
10.0.14393.9418
Microsoft Windows Server 2016<10.0.14393.9418
10.0.14393.9418
Microsoft Windows 10=1607
10.0.14393.9418
Microsoft Windows 10=1607
10.0.14393.9418
Microsoft Windows Server 2022<10.0.20348.5499, <10.0.20348.5440
10.0.20348.549910.0.20348.5440
Microsoft Windows Server 2025<10.0.26100.33296, <10.0.26100.33222
10.0.26100.3329610.0.26100.33222
Microsoft Windows Server 2025<10.0.26100.33296, <10.0.26100.33222
10.0.26100.3329610.0.26100.33222
Microsoft Windows Server 2022<10.0.20348.5499, <10.0.20348.5440
10.0.20348.549910.0.20348.5440
Microsoft Windows Server 2019<10.0.17763.9115
10.0.17763.9115
Microsoft Windows Server 2019<10.0.17763.9115
10.0.17763.9115
Microsoft Windows 10=1809
10.0.17763.9115
Microsoft Windows 10=1809
10.0.17763.9115
Microsoft Windows Server 2012 R2<6.3.9600.23338
6.3.9600.23338
Microsoft Windows Server 2012<6.2.9200.26280
6.2.9200.26280
Microsoft Windows Server 2012 R2<6.3.9600.23338
6.3.9600.23338
Microsoft Windows Server 2012<6.2.9200.26280
6.2.9200.26280
Microsoft Windows 10 1607<10.0.14393.9418
Microsoft Windows 10 1607<10.0.14393.9418
Microsoft Windows 10 1809<10.0.17763.9115
Microsoft Windows 10 1809<10.0.17763.9115
Microsoft Windows Server 2012
Microsoft Windows Server 2012=r2
Microsoft Windows Server 2016<10.0.14393.9418
Microsoft Windows Server 2019<10.0.17763.9115
Microsoft Windows Server 2022<10.0.20348.5440
Microsoft Windows Server 2025<10.0.26100.33222
Remediation
Event History
Aug 11, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:04 PM
Data Sourced
via MITRE·05:04 PM
DescriptionSeverity
Data Sourced
via NVD·05:18 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-62818?
CVE-2026-62818 has a high severity rating of 8.8.
2
What is CVE-2026-62818?
CVE-2026-62818 is a vulnerability in Windows Active Directory Certificate Services that allows remote code execution due to a use after free condition.
3
Who is affected by CVE-2026-62818?
CVE-2026-62818 affects users of various Microsoft Windows Server versions and Windows 10.
4
How do I fix CVE-2026-62818?
The recommended fix for CVE-2026-62818 is to apply the available security patch.
5
Can CVE-2026-62818 be exploited remotely?
Yes, CVE-2026-62818 can be exploited by an authorized attacker to execute code over a network.