• PATCH AVAILABLE

CVE-2026-69491: pre-auth remote code execution in Microsoft Windows 10 Version 1607

Remote unauthenticated attackers can execute arbitrary code on Windows systems that process malicious DirectMusic content; this is CVE-2026-69491. Affected builds span multiple Windows 10, Windows 11 and Windows Server 2012 branches (see vendor ranges) and are fixed in specific builds such as 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725 and later equivalents. The vulnerability is a heap-based buffer overflow (CWE-122) exploitable over the network without credentials or user interaction, according to the supplied CVSS vector.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-122
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: treat this as high priority to patch because the flaw allows unauthenticated remote code execution over the network (CVSS 9.8). Apply the vendor fixes immediately to exposed systems.

What is CVE-2026-69491?

Remote unauthenticated attackers can execute arbitrary code on Windows systems that process malicious DirectMusic content; this is CVE-2026-69491. Affected builds span multiple Windows 10, Windows 11 and Windows Server 2012 branches (see vendor ranges) and are fixed in specific builds such as 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725 and later equivalents. The vulnerability is a heap-based buffer overflow (CWE-122) exploitable over the network without credentials or user interaction, according to the supplied CVSS vector. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349

Is CVE-2026-69491 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-69491

  1. Identify affected builds using the vendor's listed build ranges and inventory tools.
  2. Install the fixed builds listed by the vendor (for example 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725 or later builds shown in the vendor data).
  3. If immediate patching is not possible, restrict network exposure of vulnerable hosts and block untrusted multimedia content sources.
  4. Monitor endpoints for signs of compromise and review network logs for suspicious DirectMusic or multimedia traffic.

Frequently asked questions

Is CVE-2026-69491 being actively exploited?

There are no public reports of exploitation as of 2026-09-29.

Which Windows versions are affected by CVE-2026-69491?

Multiple Windows 10 and Windows 11 branches and Windows Server 2012 builds are affected; the vendor provided exact build ranges for each branch (for example 10.0.14393.0 – before 10.0.14393.9512).

Is there a patch for CVE-2026-69491?

Yes. Microsoft published fixed builds for the affected branches, for example 10.0.14393.9512, 10.0.17763.9245 and 10.0.19044.7725; install the appropriate fixed build for your branch.

Does CVE-2026-69491 require authentication?

No. The vulnerability can be exploited without authentication or user interaction according to the provided CVSS vector.

References