Start with Identity

CVE-2025-58726SMB Server Kerberos reflection via Ghost SPNs

high
Product: Windows SMB ServerVendor: MicrosoftDisclosed: 2025-10-14Status: PatchedNVD ↗

What broke

CVE-2025-58726 is the October 2025 SMB Server elevation of privilege that takes CVE-2025-33073's Kerberos reflection and pairs it with Ghost SPNs created through DNS self-registration. Microsoft patched it in the October 2025 updates.

Why it matters

DNS self-registration is on by default in most AD shops. That convenience is now part of an elevation chain. KerberLoss later showed another way to play with SPN uniqueness. SPNs are identity, not inventory trivia.

What to do

  • Patch Windows Server for October 2025.
  • Disable insecure dynamic DNS updates where you can. Monitor new SPN writes on privileged computer accounts.
  • Cross-check with CVE-2026-25177 (invisible-Unicode SPN bypass) when you write the AD hardening ticket.

Sources

Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.