Skip to content
New PoC Exploit for NTLM Reflection Bypass Vulnerability on Windows Server

New PoC Exploit for NTLM Reflection Bypass Vulnerability on Windows Server

First seen 30 Jun 2026, 13:59 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •July 1, 2026 at 13:47 UTC

A proof-of-concept (PoC) exploit has been released for a NTLM reflection bypass vulnerability, tracked as CVE-2026-24294, which allows attackers to gain SYSTEM-level access on Windows Server 2025. This vulnerability arises from design flaws that were not fully addressed by the previous patch for CVE-2025-33073. The original mitigation only covered the SMB client path, leaving other vectors open for exploitation. The PoC was made public on April 30, 2026, and raises significant concerns about the effectiveness of Microsoft's authentication hardening measures. Organizations using Windows Server 2025 are at risk, particularly those that have not implemented additional security layers. The release of the PoC has prompted urgent advisories for system administrators to assess their environments and apply necessary mitigations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 91d ago How this analysis works

Timeline

2025-06-10
CVE-2025-33073 published
Microsoft disclosed an NTLM reflection vulnerability affecting Windows Server, leading to potential SYSTEM access.
Cybersecuritynews
2025-10-20
CVE-2025-33073 added to CISA KEV
CISA added the vulnerability to its Known Exploited Vulnerabilities catalog due to active exploitation.
Cybersecuritynews
2026-03-10
CVE-2026-24294 published
A new NTLM reflection bypass vulnerability was published, allowing SYSTEM-level access on Windows Server 2025.
Cybersecuritynews
2026-04-30
First public PoC for CVE-2026-24294
A working proof-of-concept exploit was released, demonstrating the vulnerability's potential for exploitation.
Gbhackers
2026-06-30
PoC exploit raises security concerns
The release of the PoC for CVE-2026-24294 has prompted urgent advisories for Windows Server 2025 users.
Cybersecuritynews

More articles in this cluster (4)

Following this threat?

Track Bumblebee and CVE-2025-33073 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed