• PATCH AVAILABLE

CVE-2026-69276: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An unauthenticated attacker can execute arbitrary code on affected Windows systems by exploiting an integer underflow in the UxTheme library; see CVE-2026-69276. The flaw impacts multiple Windows branches and builds listed by Microsoft, including Windows 10 Version 1607, 1809, 21H2, 22H2 and several Windows 11 and Windows Server 2012 builds; affected build ranges and corresponding fixed builds are provided by the vendor. Exploitation requires only network access to the vulnerable component and does not require user interaction or valid credentials.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00996
CWE
CWE-191
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent — this is an unauthenticated remote code execution bug in a network-reachable Windows component; apply Microsoft’s updates to the fixed builds immediately or otherwise isolate vulnerable hosts from untrusted networks.

What is CVE-2026-69276?

An unauthenticated attacker can execute arbitrary code on affected Windows systems by exploiting an integer underflow in the UxTheme library; see CVE-2026-69276. The flaw impacts multiple Windows branches and builds listed by Microsoft, including Windows 10 Version 1607, 1809, 21H2, 22H2 and several Windows 11 and Windows Server 2012 builds; affected build ranges and corresponding fixed builds are provided by the vendor. Exploitation requires only network access to the vulnerable component and does not require user interaction or valid credentials.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349

Is CVE-2026-69276 being exploited?

There are no public reports of active exploitation as of 2026-09-29.

How to fix CVE-2026-69276

  1. Install Microsoft’s security updates that update affected builds to the fixed builds (for example 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725 and others listed by Microsoft).
  2. Verify build numbers after patching and roll out updates across all affected Windows 10, Windows 11 and Windows Server hosts.
  3. If you cannot immediately patch, restrict network exposure of vulnerable systems and block access to services that use the UxTheme component from untrusted networks.
  4. Monitor endpoint and network logs for signs of unexpected code execution or lateral movement and follow Microsoft guidance for incident response.

Frequently asked questions

Is CVE-2026-69276 being actively exploited?

There are no public reports of exploitation of CVE-2026-69276 as of 2026-09-29.

Which Windows versions are affected by CVE-2026-69276?

Multiple Windows branches are affected, including Windows 10 Version 1607, 1809, 21H2, 22H2, several Windows 11 versions and Windows Server 2012; consult Microsoft’s affected build ranges and fixed build numbers for exact details.

Is there a patch for CVE-2026-69276?

Yes. Microsoft published updates that raise affected builds to fixed versions such as 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725 and others; install the vendor updates for your build.

Does CVE-2026-69276 require authentication?

No. The vulnerability in the UxTheme component can be exploited without authentication or user interaction on vulnerable Windows builds.

References