• PATCH AVAILABLE

CVE-2026-69431: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An unauthenticated attacker can trigger a heap-based buffer overflow in the Windows Telnet Client to run arbitrary code on affected Windows builds (CVE-2026-69431). Microsoft lists multiple affected branches including Windows 10 (various releases), Windows 11 branches, and Windows Server 2012; specific vulnerable builds run from the initial branch releases up to but not including the fixed builds shown by Microsoft. The flaw requires network access to the Telnet Client and does not require valid credentials or user interaction to exploit.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00996
CWE
CWE-122
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a remote, unauthenticated code execution bug (CVSS 9.8) that can be triggered over the network, so prioritize installing the vendor fixes for the listed builds or otherwise block Telnet exposure.

What is CVE-2026-69431?

An unauthenticated attacker can trigger a heap-based buffer overflow in the Windows Telnet Client to run arbitrary code on affected Windows builds (CVE-2026-69431). Microsoft lists multiple affected branches including Windows 10 (various releases), Windows 11 branches, and Windows Server 2012; specific vulnerable builds run from the initial branch releases up to but not including the fixed builds shown by Microsoft. The flaw requires network access to the Telnet Client and does not require valid credentials or user interaction to exploit. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349

Is CVE-2026-69431 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-69431

  1. Install Microsoft updates that move affected builds to the fixed builds (for example: 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954, 6.2.9200.26349).
  2. If you cannot apply updates immediately, restrict network exposure to the Telnet Client by blocking Telnet ports at the network edge and on hosts.
  3. Monitor network and host logs for anomalous Telnet connections and suspicious process activity on systems running affected builds.
  4. Follow Microsoft guidance for any additional mitigations or workarounds in their advisory.

Frequently asked questions

Is CVE-2026-69431 being actively exploited?

There are no public reports of exploitation of CVE-2026-69431 as of 2026-09-29.

Which Windows versions are affected by CVE-2026-69431?

Multiple Windows branches are affected, including Windows 10 releases (e.g., 1607, 1809, 21H2, 22H2), Windows 11 branches, and Windows Server 2012; Microsoft lists the exact vulnerable and fixed build numbers in its advisory.

Is there a patch for CVE-2026-69431?

Yes. Microsoft provides updates that fix the issue by advancing affected builds to specific fixed builds such as 10.0.14393.9512 and the other fixed build numbers listed by the vendor.

Does CVE-2026-69431 require authentication?

No. The vulnerability in the Windows Telnet Client can be exploited by an unauthenticated attacker over the network without user interaction.

References