• PATCH AVAILABLE

CVE-2026-68839: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An unauthenticated attacker can execute code remotely against Windows systems via a heap-based buffer overflow in the Windows USB Mass Storage Class Driver; tracked as CVE-2026-68839. Affected builds span multiple Windows 10 and Windows 11 branches (for example Windows 10 Version 1607, 1809, 21H2, 22H2 and several Windows 11 releases) and Windows Server 2012; specific affected build ranges and fixed builds are listed by the vendor. Exploitation only requires network access to an affected system using the vulnerable driver.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.01022
CWE
CWE-122
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent — this is a network-accessible, unauthenticated remote code execution vulnerability with a CVSS 9.8 and vendor fixes available; prioritize applying the provided fixed builds or block exposure of affected systems until patched.

What is CVE-2026-68839?

An unauthenticated attacker can execute code remotely against Windows systems via a heap-based buffer overflow in the Windows USB Mass Storage Class Driver; tracked as CVE-2026-68839. Affected builds span multiple Windows 10 and Windows 11 branches (for example Windows 10 Version 1607, 1809, 21H2, 22H2 and several Windows 11 releases) and Windows Server 2012; specific affected build ranges and fixed builds are listed by the vendor. Exploitation only requires network access to an affected system using the vulnerable driver. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349

Is CVE-2026-68839 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-68839

  1. Apply the vendor fixes for the affected branches (install builds listed as fixed, for example 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954, and 6.2.9200.26349).
  2. If you cannot immediately patch, restrict network exposure of systems running the vulnerable driver and block access from untrusted networks.
  3. Monitor endpoint and network logs for unusual activity and deploy intrusion detection signatures that target USB driver exploitation patterns.
  4. Follow Microsoft's guidance and update policies to ensure all affected builds are brought to the listed fixed versions.

Frequently asked questions

Is CVE-2026-68839 being actively exploited?

There are no public reports of active exploitation of CVE-2026-68839 as of 2026-09-29.

Which Windows versions are affected by CVE-2026-68839?

Windows systems using the Windows USB Mass Storage Class Driver are affected across multiple branches, including Windows 10 Version 1607, 1809, 21H2, 22H2, several Windows 11 releases (23H2, 24H2, 25H2, 26H1) and Windows Server 2012; vendor advisory lists exact build ranges and fixed builds.

Is there a patch for CVE-2026-68839?

Yes. Microsoft published fixed builds for the affected branches; the vendor advisory lists specific fixed build numbers to install for each affected branch.

Does CVE-2026-68839 require authentication?

No. The vulnerability allows unauthenticated remote code execution against the Windows USB Mass Storage Class Driver when the vulnerable driver is reachable over the network.

References