• PATCH AVAILABLE

CVE-2026-65791: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An unauthenticated attacker can execute arbitrary code on Windows systems via a heap-based buffer overflow in the Windows iSCSI Target Service. CVE-2026-65791 affects multiple Windows branches including Windows 10 Version 1607 (10.0.14393 before 10.0.14393.9418), Windows 10 Version 1809 (10.0.17763 before 10.0.17763.9121), Windows Server 2012/2012 R2, Windows Server 2016 and Windows Server 2019 (including Server Core installations); the vendor lists fixed builds for each affected branch. Exploitation requires network access to the iSCSI Target Service and no valid credentials are required.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-122
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Treat this as urgent: the flaw allows remote code execution without authentication, so prioritize installing the vendor fixes or otherwise blocking access to the iSCSI Target Service from untrusted networks.

What is CVE-2026-65791?

An unauthenticated attacker can execute arbitrary code on Windows systems via a heap-based buffer overflow in the Windows iSCSI Target Service. CVE-2026-65791 affects multiple Windows branches including Windows 10 Version 1607 (10.0.14393 before 10.0.14393.9418), Windows 10 Version 1809 (10.0.17763 before 10.0.17763.9121), Windows Server 2012/2012 R2, Windows Server 2016 and Windows Server 2019 (including Server Core installations); the vendor lists fixed builds for each affected branch. Exploitation requires network access to the iSCSI Target Service and no valid credentials are required. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.941810.0.14393.9418
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.912110.0.17763.9121
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.262806.2.9200.26280
Windows Server 2012 (Server Core installation) 6.x6.2.9200.0 – before 6.2.9200.262806.2.9200.26280
Windows Server 2012 R2 6.x6.3.9600.0 – before 6.3.9600.233386.3.9600.23338
Windows Server 2012 R2 (Server Core installation) 6.x6.3.9600.0 – before 6.3.9600.233386.3.9600.23338
Windows Server 2016 10.x10.0.14393.0 – before 10.0.14393.941810.0.14393.9418
Windows Server 2016 (Server Core installation) 10.x10.0.14393.0 – before 10.0.14393.941810.0.14393.9418
Windows Server 2019 10.x10.0.17763.0 – before 10.0.17763.912110.0.17763.9121
Windows Server 2019 (Server Core installation) 10.x10.0.17763.0 – before 10.0.17763.912110.0.17763.9121

Is CVE-2026-65791 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-65791

  1. Apply the Microsoft updates that provide the fixed builds (for example 10.0.14393.9418, 10.0.17763.9121, 6.2.9200.26280, 6.3.9600.23338)
  2. If you cannot patch immediately, block network access to the iSCSI Target Service from untrusted networks and restrict to trusted management subnets
  3. Monitor systems for unusual network activity and signs of code execution on hosts running the iSCSI Target Service and review vendor guidance for additional mitigations

Frequently asked questions

Is CVE-2026-65791 being actively exploited?

There are no public reports of exploitation of CVE-2026-65791 as of 2026-09-29.

Which Windows versions are affected by CVE-2026-65791?

CVE-2026-65791 affects Windows 10 Version 1607 and 1809 branches, Windows Server 2012 and 2012 R2, Windows Server 2016 and Windows Server 2019, including Server Core installations; affected build ranges and fixed builds are documented by the vendor.

Is there a patch for CVE-2026-65791?

Yes, Microsoft published updates that fix the vulnerability; fixed builds include 10.0.14393.9418, 10.0.17763.9121, 6.2.9200.26280 and 6.3.9600.23338 for the respective branches.

Does CVE-2026-65791 require authentication?

No. The vulnerability in the Windows iSCSI Target Service can be exploited by an unauthenticated attacker over the network.

References