Six Samba vulnerabilities, two of them at maximum severity

On 26 May the Samba project published a security announcement covering six vulnerabilities and their patches. Two carry a CVSS score of 10 and allow remote code execution. CVE-2026-4408, however, requires a non-default configuration, and CVE-2026-4480 does not work where CUPS handles printing, which is the default in most Linux distributions.

Affected organisations are advised to upgrade to a fixed release: 4.22.9, 4.23.7 or 4.24.2.

What this means for your organisation

Samba often runs quietly for years, typically as a file server for legacy systems or production equipment nobody wants to touch. Those are precisely the installations that rarely appear on a patch list. Even though both of the most severe issues carry preconditions that reduce real-world risk, you should know which Samba servers you actually operate and how they are configured.

Berigo recommends

  • Build an inventory of all Samba installations, including those bundled with storage appliances and industrial equipment.
  • Upgrade to 4.22.9, 4.23.7 or 4.24.2 depending on the release series in use.
  • Check whether any installation uses the non-default configuration that makes CVE-2026-4408 exploitable.
  • Confirm that no Samba server is exposed directly to the internet.

Source

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch