CVE-2026-78445 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
CVSS 9.8
CRITICAL
Critical - Same Day Deployment
“A single specially crafted NFS request could give an unauthenticated attacker a path to remote code execution on a vulnerable server.”
CVE-2026-78445 is a critical use-after-free vulnerability in the Windows Services for NFS ONCRPC XDR Driver. An unauthorized remote attacker can exploit the flaw by sending a specially crafted, unauthenticated call to a Network File System (NFS) service, potentially achieving remote code execution. The vulnerability requires no privileges or user interaction and has low attack complexity.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-416
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.