Multiple critical Samba flaws have highlighted how non-default but dangerous configurations can turn exposed file-sharing infrastructure into a remote code execution path. CVE-2025-10230 affects Samba's WINS server on Active Directory Domain Controllers when WINS support is enabled and a non-empty wins hook is configured, allowing an unauthenticated attacker to send a crafted WINS registration packet to UDP port 137 and inject shell metacharacters into a command executed by Samba, potentially with root privileges. Separately, CVE-2026-4480 and CVE-2026-4408, both rated CVSS 10.0, affect Samba's printing subsystem and DCE/RPC SAMR server when administrators use vulnerable print command or check password script settings with %J or %u substitution characters.
Samba issued fixes for the WINS flaw in versions 4.23.2, 4.22.5, and 4.21.9, and for the later command-injection issues in 4.22.10, 4.23.8, and 4.24.3. Reporting on internet exposure said more than 63,000 Samba assets were reachable on TCP 445, underscoring the risk that misconfigured public SMB services could be used for server takeover, credential theft, ransomware deployment, and lateral movement. Defenders were urged to patch affected releases, audit smb.conf for risky wins hook, print command, and password-check script settings, monitor UDP 137 and SMB activity for suspicious behavior, and restrict external access with firewalls, VPNs, or IP allowlists.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
As of June 2026, the article states that Criminal IP Asset Search identified 63,055 Samba assets exposed on TCP port 445. It highlights the largest concentrations in Pakistan, the United States, Portugal, Germany, and Réunion.
On May 26, 2026, the Samba Team patched two CVSS 10.0 vulnerabilities, CVE-2026-4480 and CVE-2026-4408, in versions 4.22.10, 4.23.8, and 4.24.3. The issues affect specific non-default print command and password-check script configurations.
Samba released fixes for the WINS server command injection vulnerability CVE-2025-10230 in versions 4.23.2, 4.22.5, and 4.21.9. The flaw can allow unauthenticated remote code execution on affected non-default Samba AD DC configurations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
osintteam.blog
Open sourcezeropath.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.