# Samba patches multiple vulnerabilities

Published: 2026-07-28 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/6f2e7321-3c6f-56ab-a7e8-0f7ce5258f80/samba-patches-multiple-vulnerabilities

> ANSSI advises multiple Samba vulnerabilities allow remote denial of service, data confidentiality breach, and security policy bypass.

ANSSI (CERT-FR) has published an advisory covering multiple vulnerabilities in Samba, the open-source implementation of the SMB/CIFS networking protocol widely used for file and print services and interoperability with Windows environments. The flaws affect Samba versions 4.23.x prior to 4.23.9, 4.24.x prior to 4.24.4, and versions prior to 4.22.10.

The vulnerabilities, tracked under CVE-2026-58216, CVE-2026-58218, CVE-2026-58221, CVE-2026-58222, CVE-2026-58224, CVE-2026-6949, and CVE-2025-58218, could allow an attacker to trigger a remote denial of service, compromise data confidentiality, or bypass security policy enforcement. No active exploitation has been reported. Administrators are advised to apply the patches referenced in the official Samba security bulletins as soon as possible.

## Mentioned in this report

- Vulnerabilities: CVE-2025-58218, CVE-2026-58216, CVE-2026-58218, CVE-2026-58221, CVE-2026-58222, CVE-2026-58224, CVE-2026-6949

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0939

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/6f2e7321-3c6f-56ab-a7e8-0f7ce5258f80/samba-patches-multiple-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
