Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-08-12 ยท updated: 2026-08-12 ยท tags: [cve, rce, microsoft, wds, tftp, unauthenticated, patch-tuesday] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government, education] ยท au_impact: false

CVE-2026-62893 โ€” Windows Deployment Services TFTP RCE

CVE-2026-62893 is an unauthenticated remote code execution (RCE) vulnerability in Windows Deployment Services (WDS), reachable via TFTP, rated CVSS 9.8 and shipped in Microsoft's August 2026 Patch Tuesday release (2026-08-11).

Vulnerability Details

Attribute Detail
CVE CVE-2026-62893
Type Unauthenticated remote code execution (RCE)
Product Microsoft Windows Deployment Services (WDS)
Access Unauthenticated (via TFTP)
CVSS 9.8
Exploitation status Not flagged as actively exploited in the wild in the August 2026 release

Context

Patched in Microsoft's August 2026 Patch Tuesday (398 CVEs, 62 Critical per ZDI). CVE-2026-62893 is one of four unauthenticated RCE flaws at CVSS 9.8 in that release, alongside Windows DNS Server, Microsoft QUIC and HPC Pack. Windows Deployment Services is used to deploy Windows images over the network, commonly in enterprise and education fleets.

Mitigation

  1. Apply the August 2026 Windows security updates
  2. Restrict network access to WDS/TFTP services where it is not required

Sources: raw/digests/Cyber-Digest-2026-08-12