DIRAS TAKE
Patch urgently: this is a remotely exploitable, pre-auth code execution bug and Microsoft has issued fixed builds for all affected branches; prioritize deployment on internet-facing Windows 11 and Server hosts.
What is CVE-2026-62815?
An unauthenticated attacker can execute arbitrary code on Windows 11 systems via a use-after-free vulnerability in Microsoft QUIC. CVE-2026-62815 affects multiple Windows 11 branches and some Windows Server releases; affected builds include 10.0.22631.0 through before 10.0.22631.7517, 10.0.26100.0 through before 10.0.26100.9168, 10.0.26200.0 through before 10.0.26200.9168, and 10.0.28000.0 through before 10.0.28000.2704, plus listed Windows Server builds. The flaw can be triggered over the network without privileges or user interaction. The weakness is classified as CWE-416 (Use After Free).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 11 version 23H2 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 11 version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7517 | 10.0.22631.7517 |
| Windows 11 Version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7517 | 10.0.22631.7517 |
| Windows 11 Version 24H2 10.x | 10.0.26100.0 – before 10.0.26100.9168 | 10.0.26100.9168 |
| Windows 11 Version 25H2 10.x | 10.0.26200.0 – before 10.0.26200.9168 | 10.0.26200.9168 |
| Windows 11 version 26H1 10.x | 10.0.28000.0 – before 10.0.28000.2704 | 10.0.28000.2704 |
| Windows Server 2022 10.x | 10.0.20348.0 – before 10.0.20348.5499 | 10.0.20348.5499 |
| Windows Server 2025 10.x | 10.0.26100.0 – before 10.0.26100.33296 | 10.0.26100.33296 |
| Windows Server 2025 (Server Core installation) 10.x | 10.0.26100.0 – before 10.0.26100.33296 | 10.0.26100.33296 |
Is CVE-2026-62815 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-62815
- Install Microsoft updates that include the fixes: 10.0.22631.7517, 10.0.26100.9168, 10.0.26200.9168, 10.0.28000.2704, and applicable Windows Server fixes listed in vendor guidance.
- If you cannot patch immediately, restrict network exposure to QUIC endpoints and block untrusted inbound traffic to affected hosts.
- Monitor network and endpoint logs for anomalous QUIC connections and indicators of compromise and apply vendor-recommended detection rules.
- Follow Microsoft’s advisory for any additional mitigations and verify successful installation of the listed fixed builds.
Frequently asked questions
Is CVE-2026-62815 being actively exploited?
There are no public reports of exploitation of CVE-2026-62815 as of 2026-09-29.
Which Windows 11 versions are affected by CVE-2026-62815?
Windows 11 branches affected include builds 10.0.22631.0 through before 10.0.22631.7517, 10.0.26100.0 through before 10.0.26100.9168, 10.0.26200.0 through before 10.0.26200.9168, and 10.0.28000.0 through before 10.0.28000.2704.
Is there a patch for CVE-2026-62815?
Yes. Microsoft published fixes; fixed builds include 10.0.22631.7517, 10.0.26100.9168, 10.0.26200.9168, 10.0.28000.2704 and corresponding Windows Server fixed builds.
Does CVE-2026-62815 require authentication?
No. The vulnerability can be exploited without privileges or user interaction against affected Windows 11 systems running Microsoft QUIC.
References
- nvd.nist.gov/vuln/detail/CVE-2026-62815
- cve.org/CVERecord?id=CVE-2026-62815
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62815
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026