CVE-2026-33826

HIGH WAF: Medium
CVSS 8.0 Published: 2026-04-14
CWE-20

Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.

WAF Coverage Analysis

Improper Input Validation Medium WAF Coverage

OWASP: A03:2021 Injection

920xxx - Protocol Enforcement 941xxx - XSS / XXE 942xxx - SQL Injection

Affected Software

VendorProductVersion
microsoftwindows_server_2012r2
microsoftwindows_server_2016up to 10.0.14393.9060
microsoftwindows_server_2019up to 10.0.17763.8644
microsoftwindows_server_2022up to 10.0.20348.5020
microsoftwindows_server_2022_23h2up to 10.0.25398.2274
microsoftwindows_server_2025up to 10.0.26100.32690

References

Back to CVE Database