• PATCH AVAILABLE

CVE-2026-69463: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An unauthenticated attacker can execute arbitrary code remotely on Windows hosts by exploiting a heap-based buffer overflow in the NTFS component (CVE-2026-69463). Affected builds include Windows 10 (1607 and later servicing branches listed), multiple Windows 11 branches, and Windows Server 2012 builds prior to the fixed updates; specific fixed builds are provided by Microsoft. The vulnerability can be triggered over a network and does not require user interaction or credentials, so network exposure is sufficient for exploitation.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-122
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a network-facing, no-authentication remote code execution flaw (CVSS 9.8) — prioritize applying the vendor fixes for the listed builds and block unnecessary NTFS network exposure.

What is CVE-2026-69463?

An unauthenticated attacker can execute arbitrary code remotely on Windows hosts by exploiting a heap-based buffer overflow in the NTFS component (CVE-2026-69463). Affected builds include Windows 10 (1607 and later servicing branches listed), multiple Windows 11 branches, and Windows Server 2012 builds prior to the fixed updates; specific fixed builds are provided by Microsoft. The vulnerability can be triggered over a network and does not require user interaction or credentials, so network exposure is sufficient for exploitation. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349

Is CVE-2026-69463 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-69463

  1. Apply Microsoft updates that install the fixed builds (examples: 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954, 6.2.9200.26349).
  2. Immediately restrict network exposure to NTFS services and block SMB/NTFS access from untrusted networks.
  3. Monitor endpoints and network logs for signs of anomalous NTFS activity and unexpected code execution.
  4. Follow Microsoft's guidance for any additional mitigations or workarounds until systems are updated.

Frequently asked questions

Is CVE-2026-69463 being actively exploited?

There are no public reports of active exploitation of CVE-2026-69463 as of 2026-09-29.

Which Windows 10 Version 1607 versions are affected by CVE-2026-69463?

Windows 10 Version 1607 builds from 10.0.14393.0 up to but not including 10.0.14393.9512 are affected; apply the update to reach 10.0.14393.9512 or later.

Is there a patch for CVE-2026-69463?

Yes. Microsoft published fixes; affected branches have specific fixed builds such as 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954, and 6.2.9200.26349.

Does CVE-2026-69463 require authentication?

No. The NTFS heap overflow can be exploited over a network without authentication or user interaction.

References