Six Samba vulnerabilities, two of them at maximum severity
On 26 May the Samba project published a security announcement covering six vulnerabilities and their patches. Two carry a CVSS score of 10 and allow remote code execution. CVE-2026-4408, however, requires a non-default configuration, and CVE-2026-4480 does not work where CUPS handles printing, which is the default in most Linux distributions.
Affected organisations are advised to upgrade to a fixed release: 4.22.9, 4.23.7 or 4.24.2.
What this means for your organisation
Samba often runs quietly for years, typically as a file server for legacy systems or production equipment nobody wants to touch. Those are precisely the installations that rarely appear on a patch list. Even though both of the most severe issues carry preconditions that reduce real-world risk, you should know which Samba servers you actually operate and how they are configured.
Berigo recommends
- Build an inventory of all Samba installations, including those bundled with storage appliances and industrial equipment.
- Upgrade to 4.22.9, 4.23.7 or 4.24.2 depending on the release series in use.
- Check whether any installation uses the non-default configuration that makes CVE-2026-4408 exploitable.
- Confirm that no Samba server is exposed directly to the internet.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch