The Samba project released security updates for versions 4.22.10, 4.23.8, and 4.24.3 to fix six vulnerabilities spanning file sharing, Active Directory, DCE/RPC, certificate enrollment, and printing. The most severe issues are two unauthenticated remote code execution flaws: CVE-2026-4408 in the SAMR password validation path, where shell metacharacters in the %u substitution can be abused through crafted RPC requests when the check password script feature is enabled under specific non-default conditions, and CVE-2026-4480 in the printing subsystem under similarly specific configurations. Samba said affected systems include file servers, classic non-AD domain controllers, and print servers, while Active Directory Domain Controllers are not affected by the SAMR RCE issue.
The same release also patched CVE-2026-1933, which lets authenticated users bypass read only = yes restrictions by modifying reparse points when they also have underlying filesystem write access, and CVE-2026-3012, which allowed Group Policy certificate auto-enrollment to fetch CA certificates over plaintext HTTP and install them without validation, enabling adjacent-network trust-store poisoning and TLS interception. Ubuntu issued USN-8306-1 for supported releases, and downstream vendors including Red Hat, Debian, and SUSE also published advisories or updates. Administrators were advised to apply standard package updates promptly, especially where non-default Samba password-checking, printing, or certificate auto-enrollment features are enabled.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-26, Ubuntu published security notice USN-8306-1 covering multiple Samba vulnerabilities across Ubuntu 22.04 LTS, 24.04 LTS, 25.10, and 26.04 LTS. The notice provided fixed package versions and advised users to apply standard system updates.
On 2026-05-26, the Samba project released security updates including versions 4.22.10 and 4.24.3 to fix six vulnerabilities affecting file sharing, Active Directory, DCE/RPC, and printing-related functionality. The fixes included CVE-2026-1933, CVE-2026-3012, CVE-2026-4408, and another unauthenticated RCE in the printing subsystem.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
zeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourceubuntu.com
Open sourcesamba.org
Open sourcesamba.org
Open sourcesamba.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.