DIRAS TAKE
Urgent: apply the vendor fixes immediately because public exploit code exists for this untrusted-search-path privilege escalation. Patch exposed and reachable systems without delay.
What is CVE-2026-69328?
A local, authorized attacker can elevate privileges on Windows 10 Version 1607 and related Windows releases by exploiting an untrusted search path in Windows storage components (CVE-2026-69328). Affected builds span multiple Windows 10, Windows 11, and Windows Server branches (for example 10.0.14393.0 through before 10.0.14393.9512 for Version 1607); an attacker requires local access and an authorized account to trigger the issue.
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 10 Version 1607 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1607 10.x | 10.0.14393.0 – before 10.0.14393.9512 | 10.0.14393.9512 |
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9245 | 10.0.17763.9245 |
| Windows 10 Version 21H2 10.x | 10.0.19044.0 – before 10.0.19044.7725 | 10.0.19044.7725 |
| Windows 10 Version 22H2 10.x | 10.0.19045.0 – before 10.0.19045.7725 | 10.0.19045.7725 |
| Windows 11 version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 24H2 10.x | 10.0.26100.0 – before 10.0.26100.9445 | 10.0.26100.9445 |
| Windows 11 Version 25H2 10.x | 10.0.26200.0 – before 10.0.26200.9445 | 10.0.26200.9445 |
| Windows 11 version 26H1 10.x | 10.0.28000.0 – before 10.0.28000.2954 | 10.0.28000.2954 |
| Windows Server 2016 10.x | 10.0.14393.0 – before 10.0.14393.9512 | 10.0.14393.9512 |
Is CVE-2026-69328 being exploited?
Public exploit code is available.
How to fix CVE-2026-69328
- Install the provided security updates that include the fixes (for example update Version 1607 to 10.0.14393.9512).
- Update other affected branches to their fixed builds (examples: 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954).
- If you cannot patch immediately, restrict local access to affected systems and monitor for suspicious local privilege escalation activity.
- Follow Microsoft guidance and verify installations by checking build numbers after updates are applied.
Frequently asked questions
Is CVE-2026-69328 being actively exploited?
Public exploit code is available for CVE-2026-69328.
Which Windows 10 Version 1607 versions are affected by CVE-2026-69328?
Windows 10 Version 1607 builds from 10.0.14393.0 up to but not including 10.0.14393.9512 are affected.
Is there a patch for CVE-2026-69328?
Yes. Microsoft released fixed builds such as 10.0.14393.9512 for Version 1607 and corresponding fixed builds for other affected branches.
Does CVE-2026-69328 require authentication?
Yes. The issue requires a local, authorized user account to exploit the untrusted search path vulnerability.
References
- nvd.nist.gov/vuln/detail/CVE-2026-69328
- cve.org/CVERecord?id=CVE-2026-69328
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69328
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026