Samba 4.25.0 is available with support for SMB3 persistent handles, enabling eligible open files to recover after connection failures and supporting transparent-failover deployments. The release also introduces vfs_aio_ratelimit, which uses the ratelimitd daemon to apply shared asynchronous-I/O limits, and vfs_ceph_rgw for exporting Ceph Object Gateway storage through SMB.
The update adds Active Directory cluster functional-level management to facilitate rolling upgrades and changes the default Kerberos encryption settings. It also fixes CVE-2026-20833, an interoperability issue affecting Windows Kerberos authentication; organizations running Samba Active Directory domain controllers or SMB services should assess upgrade compatibility and deploy the release through their standard change process.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
Samba 4.25.0 was released, adding SMB3 persistent-handle support, new VFS modules, and Active Directory cluster functional-level management. The release also fixes CVE-2026-20833, a Windows Kerberos authentication interoperability issue, and changes Kerberos encryption defaults for functional levels 2008 and later.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.