As announced in January 2026, the unattend.xml file used in hands‑free deployment poses a vulnerability when transmitted over an unauthenticated RPC channel. Beginning with the April 2026 security update, IT admins should prepare for the second phase of hardening for CVE-2026-0386. These changes will make hands‑free deployment disabled by default to enforce secure behavior. After this update, hands‑free deployment will no longer work unless explicitly overridden with registry settings. When will...
Applies to: Windows
Source: mc.merill.net — data via Merill Fernando's open archive (MIT).