cbcvebase.
CVE-2026-40413
published 2026-05-12

CVE-2026-40413: Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over an adjacent network.

PriorityP337high7.4CVSS 3.1
AVAACLPRNUINSCCNINAH
EPSS
0.40%
32.4th percentile
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over an adjacent network.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1607< 10.0.14393.914010.0.14393.9140
microsoftwindows_10_1809< 10.0.17763.875510.0.17763.8755
microsoftwindows_10_21h2< 10.0.19044.729110.0.19044.7291
microsoftwindows_10_22h2< 10.0.19045.729110.0.19045.7291
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.914010.0.14393.9140
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.875510.0.17763.8755
microsoftwindows_10_version_21h2>= 10.0.19044.0 < 10.0.19044.729110.0.19044.7291
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.741710.0.19045.7417
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.729110.0.19045.7291
microsoftwindows_11_23h2< 10.0.22631.707910.0.22631.7079
microsoftwindows_11_24h2< 10.0.26100.839010.0.26100.8390
microsoftwindows_11_25h2< 10.0.26200.839010.0.26200.8390
microsoftwindows_11_26h1< 10.0.28000.211310.0.28000.2113
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.707910.0.22631.7079
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.707910.0.22631.7079
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.721910.0.22631.7219
microsoftwindows_11_version_24h2>= 10.0.26100.0 < 10.0.26100.845710.0.26100.8457
microsoftwindows_11_version_25h2>= 10.0.26200.0 < 10.0.26200.845710.0.26200.8457
microsoftwindows_11_version_26h1>= 10.0.28000.0 < 10.0.28000.211310.0.28000.2113
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.260796.2.9200.26079
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.231816.3.9600.23181
microsoftwindows_server_2016< 10.0.14393.914010.0.14393.9140
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.914010.0.14393.9140
microsoftwindows_server_2019< 10.0.17763.875510.0.17763.8755

CVSS provenance

nvdv3.17.4HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
cvelistv5v3.17.4HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.