DIRAS TAKE
Treat this as urgent: the flaw allows remote code execution without authentication, so prioritize installing the vendor fixes or otherwise blocking access to the iSCSI Target Service from untrusted networks.
What is CVE-2026-65791?
An unauthenticated attacker can execute arbitrary code on Windows systems via a heap-based buffer overflow in the Windows iSCSI Target Service. CVE-2026-65791 affects multiple Windows branches including Windows 10 Version 1607 (10.0.14393 before 10.0.14393.9418), Windows 10 Version 1809 (10.0.17763 before 10.0.17763.9121), Windows Server 2012/2012 R2, Windows Server 2016 and Windows Server 2019 (including Server Core installations); the vendor lists fixed builds for each affected branch. Exploitation requires network access to the iSCSI Target Service and no valid credentials are required. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 10 Version 1607 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1607 10.x | 10.0.14393.0 – before 10.0.14393.9418 | 10.0.14393.9418 |
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9121 | 10.0.17763.9121 |
| Windows Server 2012 6.x | 6.2.9200.0 – before 6.2.9200.26280 | 6.2.9200.26280 |
| Windows Server 2012 (Server Core installation) 6.x | 6.2.9200.0 – before 6.2.9200.26280 | 6.2.9200.26280 |
| Windows Server 2012 R2 6.x | 6.3.9600.0 – before 6.3.9600.23338 | 6.3.9600.23338 |
| Windows Server 2012 R2 (Server Core installation) 6.x | 6.3.9600.0 – before 6.3.9600.23338 | 6.3.9600.23338 |
| Windows Server 2016 10.x | 10.0.14393.0 – before 10.0.14393.9418 | 10.0.14393.9418 |
| Windows Server 2016 (Server Core installation) 10.x | 10.0.14393.0 – before 10.0.14393.9418 | 10.0.14393.9418 |
| Windows Server 2019 10.x | 10.0.17763.0 – before 10.0.17763.9121 | 10.0.17763.9121 |
| Windows Server 2019 (Server Core installation) 10.x | 10.0.17763.0 – before 10.0.17763.9121 | 10.0.17763.9121 |
Is CVE-2026-65791 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-65791
- Apply the Microsoft updates that provide the fixed builds (for example 10.0.14393.9418, 10.0.17763.9121, 6.2.9200.26280, 6.3.9600.23338)
- If you cannot patch immediately, block network access to the iSCSI Target Service from untrusted networks and restrict to trusted management subnets
- Monitor systems for unusual network activity and signs of code execution on hosts running the iSCSI Target Service and review vendor guidance for additional mitigations
Frequently asked questions
Is CVE-2026-65791 being actively exploited?
There are no public reports of exploitation of CVE-2026-65791 as of 2026-09-29.
Which Windows versions are affected by CVE-2026-65791?
CVE-2026-65791 affects Windows 10 Version 1607 and 1809 branches, Windows Server 2012 and 2012 R2, Windows Server 2016 and Windows Server 2019, including Server Core installations; affected build ranges and fixed builds are documented by the vendor.
Is there a patch for CVE-2026-65791?
Yes, Microsoft published updates that fix the vulnerability; fixed builds include 10.0.14393.9418, 10.0.17763.9121, 6.2.9200.26280 and 6.3.9600.23338 for the respective branches.
Does CVE-2026-65791 require authentication?
No. The vulnerability in the Windows iSCSI Target Service can be exploited by an unauthenticated attacker over the network.
References
- nvd.nist.gov/vuln/detail/CVE-2026-65791
- cve.org/CVERecord?id=CVE-2026-65791
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65791
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026