8.3

CVE-2026-56181

Media report

Windows Network Address Translation (NAT) Spoofing Vulnerability

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows 11 24h2 Version < 10.0.26100.8875
MicrosoftWindows 11 25h2 Version < 10.0.26200.8875
MicrosoftWindows 11 26h1 Version < 10.0.28000.2525
MicrosoftWindows Server 2025 Version < 10.0.26100.33158
VulnDex Vulnerability Enrichment
This information is available to logged-in users. Login Login
No warning was found for this CVE.
EPSS Metrics
Type Source Score Percentile
EPSS FIRST.org 0.24% 0.148
CVSS Metrics
Source Base Score Exploit Score Impact Score Vector string
Microsoft 8.3 1.6 6
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-346 Origin Validation Error

The product does not properly verify that the source of data or communication is valid.

A VulnDex account is required to access Vulnerability Intelligence.
VulnDex Intel
Media Report
10.08.2026 18:54
A VulnDex account is required to access Vulnerability Intelligence.
VulnDex Intel
Media Report
07.08.2026 12:01
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56181
Patch
Vendor Advisory