PT-2026-32734 · Microsoft · Windows Server 2012+2

Published

2026-04-14

·

Updated

2026-04-17

·

CVE-2026-26154

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows Server 2012 versions 6.2.9200.0 through 6.2.9200.26025
Description Improper input validation in Windows Server Update Service (WSUS) allows an unauthorized attacker to perform tampering over a network, which could potentially enable the deployment of malicious updates.
Recommendations Update Microsoft Windows Server 2012 to version 6.2.9200.26026 or later.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2026-05472
CVE-2026-26154

Affected Products

Windows
Windows Server 2012
Windows Server Update Services