Windows Active Directory Domain Services Remote Code Execution Vulnerability

Date Aug 11, 2026
Type Patch Tuesday
Signal High-risk advisory
Vendor / Product Microsoft ยท Windows Active Directory
CVE CVE-2026-49179
High-risk advisory CVE-2026-49179

Summary

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely.

Why it matters

Microsoft published this item through its Security Update Guide, making it part of Patch Tuesday triage for affected Windows, cloud, or application estates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-49179. Confirm whether Windows Active Directory is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.