CVE-2026-69374: Windows SMB Server Denial of Service Vulnerability
Published Sep 8, 2026
·Updated
Allocation of resources without limits or throttling in Windows SMB Server allows an authorized attacker to deny service over a network.
Other sources
Windows SMB Server Denial of Service Vulnerability
— Microsoft
Affected Software
1 affected component
Microsoft Windows SMB Server
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
CVE Published
via MITRE·05:15 PM
Data Sourced
via MITRE·05:15 PM
DescriptionSeverity
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
An attacker must be authorized and able to reach the affected Windows SMB Server over the network. The vulnerability does not require user interaction.
2
What is the likely impact of successful exploitation?
Successful exploitation can deny service by causing the Windows SMB Server to allocate resources without limits or throttling. The provided metrics indicate availability impact, with no stated confidentiality or integrity impact.
3
Is this exploitable remotely?
Yes. The attack vector is network-based, so exploitation can be attempted by an authorized attacker with network access to the SMB service.