Summary
Windows Active Directory on Windows Server domain controllers lets an authenticated attacker send a crafted RPC call that bypasses input validation and runs code on the RPC host with service-level permissions. The issue requires a low-privilege account in the same restricted AD domain and no user interaction, so it is most dangerous in organizations with internally reachable domain infrastructure. Successful exploitation can lead to arbitrary code execution on the affected server.
Why Planned Fix?
3/6Exploitation Details
Execute arbitrary code on the affected server with RPC service permissions
RCE (Remote Code Execution)Affected Software
| Product | Affected Versions |
|---|---|
| Windows Active Directory | Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, Windows Server 2025, and Windows Server version 23H2 |
Microsoft's directory service for Windows domains that centralizes authentication, authorization, and identity management.
Affected ComponentRPC request handling in Windows Active Directory on domain controllers.
RPC request handling in Windows Active Directory on domain controllers.
Not available
Apply the April 14, 2026 Microsoft security update for your Windows Server release: KB5082063 (Server 2025), KB5082142 (Server 2022 / Azure Stack HCI 22H2), KB5082123 (Server 2019), KB5082198 (Server 2016), KB5082126 (Server 2012 R2), or KB5082060 (Server version 23H2).
Apply the April 14, 2026 Microsoft security update for your Windows Server release: KB5082063 (Server 2025), KB5082142 (Server 2022 / Azure Stack HCI 22H2), KB5082123 (Server 2019), KB5082198 (Server 2016), KB5082126 (Server 2012 R2), or KB5082060 (Server version 23H2).
Not available
Probability of exploitation in the next 30 days
Worse than 59% of all CVEs
No known threat actors
No detection rules available
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Sources
| Source | Article |
|---|---|
| msrc.microsoft.com | CVE-2026-33826 Security Update Guide |
| crowdstrike.com | April 2026 Patch Tuesday Analysis |
| tenable.com | CVE-2026-33826 |
| tenable.com | CVE-2026-33826 Plugins |
Priority History
Initial analysis