type: cve ยท created: 2026-08-12 ยท updated: 2026-08-12 ยท tags: [cve, rce, microsoft, wds, tftp, unauthenticated, patch-tuesday] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government, education] ยท au_impact: false
CVE-2026-62893 โ Windows Deployment Services TFTP RCE
CVE-2026-62893 is an unauthenticated remote code execution (RCE) vulnerability in Windows Deployment Services (WDS), reachable via TFTP, rated CVSS 9.8 and shipped in Microsoft's August 2026 Patch Tuesday release (2026-08-11).
Vulnerability Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-62893 |
| Type | Unauthenticated remote code execution (RCE) |
| Product | Microsoft Windows Deployment Services (WDS) |
| Access | Unauthenticated (via TFTP) |
| CVSS | 9.8 |
| Exploitation status | Not flagged as actively exploited in the wild in the August 2026 release |
Context
Patched in Microsoft's August 2026 Patch Tuesday (398 CVEs, 62 Critical per ZDI). CVE-2026-62893 is one of four unauthenticated RCE flaws at CVSS 9.8 in that release, alongside Windows DNS Server, Microsoft QUIC and HPC Pack. Windows Deployment Services is used to deploy Windows images over the network, commonly in enterprise and education fleets.
Mitigation
- Apply the August 2026 Windows security updates
- Restrict network access to WDS/TFTP services where it is not required
Sources: raw/digests/Cyber-Digest-2026-08-12