VORANT. Threat Intelligence Sign in Get the full feed

Six vulnerabilities in Samba versions prior to 4.22.10, 4.23.8, and 4.24.3 enable remote…

critical vulnerability

Six vulnerabilities in Samba versions prior to 4.22.10, 4.23.8, and 4.24.3 enable remote code execution, denial of service, and data integrity attacks.

The French national CERT (CERT-FR) has issued an advisory regarding multiple critical vulnerabilities discovered in Samba, the open-source implementation of the SMB/CIFS networking protocol widely used for file and print sharing across networks. Six CVEs have been identified (CVE-2026-1933, CVE-2026-2340, CVE-2026-3012, CVE-2026-3238, CVE-2026-4408, CVE-2026-4480) affecting Samba versions prior to 4.22.10, 4.23.8, and 4.24.3.

The vulnerabilities present several attack vectors including remote arbitrary code execution, remote denial of service, security policy bypass, and data integrity compromise. Given Samba's ubiquitous deployment in enterprise environments for network file sharing and Active Directory integration, these flaws pose significant risk to organizations running vulnerable versions. The vendor has released patches for all affected versions, and administrators should prioritize applying updates to mitigate exploitation risk.

Organizations should immediately inventory their Samba deployments, identify vulnerable versions, and apply the vendor-supplied patches. Network segmentation and access controls should be reviewed to limit potential exposure while patching is underway.

Mentioned in this report

Vulnerabilities CVE-2026-1933CVE-2026-2340CVE-2026-3012CVE-2026-3238CVE-2026-4408CVE-2026-4480templated

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0651

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free