ThreatCluster

Windows SMB Client Vulnerability Allows Active Directory Compromise

First seen 19 Jan 2026, 18:31 UTC CybersecuritynewsGbhackers 26

Article Content

Browse articles
ThreatCluster

A critical vulnerability in Windows SMB client authentication has been identified, enabling attackers to exploit NTLM reflection to compromise Active Directory environments. This improper access control vulnerability allows authorized attackers to escalate privileges through authentication relay attacks over network connections. Organizations that rely on Windows SMB are at risk of full Active Directory compromise.