cbcvebase.
CVE-2026-40405
published 2026-05-12

CVE-2026-40405: Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.

Affected

8 ranges
VendorProductVersion rangeFixed in
microsoftwindows_11_24h2< 10.0.26100.839010.0.26100.8390
microsoftwindows_11_25h2< 10.0.26200.839010.0.26200.8390
microsoftwindows_11_26h1< 10.0.28000.211310.0.28000.2113
microsoftwindows_11_version_24h2>= 10.0.26100.0 < 10.0.26100.845710.0.26100.8457
microsoftwindows_11_version_25h2>= 10.0.26200.0 < 10.0.26200.845710.0.26200.8457
microsoftwindows_11_version_26h1>= 10.0.28000.0 < 10.0.28000.211310.0.28000.2113
microsoftwindows_server_2025< 10.0.26100.3277210.0.26100.32772
microsoftwindows_server_2025>= 10.0.26100.0 < 10.0.26100.3286010.0.26100.32860