• PATCH AVAILABLE

CVE-2026-69408: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An unauthenticated attacker can execute code on affected Microsoft Windows systems via an integer overflow in Windows Media Foundation (CVE-2026-69408). The flaw affects multiple Windows branches and builds, including Windows 10 Version 1607 (10.0.14393.0 through before 10.0.14393.9512), several Windows 10 and Windows 11 branches, and Windows Server 2012 builds listed in the vendor advisory. An attacker only needs network access to trigger the overflow; no user interaction or valid account is required.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-190
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a network-accessible, no-auth remote code execution with critical impact and vendor fixes released; prioritize applying the supplied security updates to affected builds immediately.

What is CVE-2026-69408?

An unauthenticated attacker can execute code on affected Microsoft Windows systems via an integer overflow in Windows Media Foundation (CVE-2026-69408). The flaw affects multiple Windows branches and builds, including Windows 10 Version 1607 (10.0.14393.0 through before 10.0.14393.9512), several Windows 10 and Windows 11 branches, and Windows Server 2012 builds listed in the vendor advisory. An attacker only needs network access to trigger the overflow; no user interaction or valid account is required.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349

Is CVE-2026-69408 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-69408

  1. Apply the Microsoft updates that include the fixes (for example upgrade Windows 10 Version 1607 to build 10.0.14393.9512).
  2. Upgrade other affected branches to their fixed builds (for example 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954, and Windows Server 2012 6.2.9200.26349).
  3. Reduce network exposure of vulnerable hosts until patched by restricting access to Media Foundation services and blocking unnecessary inbound media streaming protocols.
  4. Monitor endpoint and network logs for suspicious executions and indicators of compromise targeting media processing components.

Frequently asked questions

Is CVE-2026-69408 being actively exploited?

There are no public reports of exploitation of CVE-2026-69408 as of 2026-09-29.

Which Windows 10 Version 1607 versions are affected by CVE-2026-69408?

Windows 10 Version 1607 builds from 10.0.14393.0 through before 10.0.14393.9512 are affected; the issue is fixed in build 10.0.14393.9512.

Is there a patch for CVE-2026-69408?

Yes. Microsoft released fixes; affected branches have specific fixed builds such as 10.0.14393.9512 for Windows 10 Version 1607 and corresponding fixed builds listed by Microsoft for other Windows versions.

Does CVE-2026-69408 require authentication?

No. The vulnerability in Windows Media Foundation can be triggered by an unauthenticated attacker over the network.

References