THREAT OPS › Threat News › [NVD] CVE-2026-3012 (HIGH 8.0) — A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker w
[NVD] CVE-2026-3012 (HIGH 8.0) — A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker w
CVE-2026-3012 CVSS: 8.0 HIGH Published: 2026-05-27T11:16:18.357
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffi
Indicators of compromise
- CVE-2026-3012cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-3012