CVE-2026-78445 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability

CVSS 9.8 CRITICAL Critical - Same Day Deployment

“A single specially crafted NFS request could give an unauthenticated attacker a path to remote code execution on a vulnerable server.”

CVE-2026-78445 is a critical use-after-free vulnerability in the Windows Services for NFS ONCRPC XDR Driver. An unauthorized remote attacker can exploit the flaw by sending a specially crafted, unauthenticated call to a Network File System (NFS) service, potentially achieving remote code execution. The vulnerability requires no privileges or user interaction and has low attack complexity.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-416
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.