DIRAS TAKE
Urgent: treat this as high priority to patch because the flaw allows unauthenticated remote code execution over the network (CVSS 9.8). Apply the vendor fixes immediately to exposed systems.
What is CVE-2026-69491?
Remote unauthenticated attackers can execute arbitrary code on Windows systems that process malicious DirectMusic content; this is CVE-2026-69491. Affected builds span multiple Windows 10, Windows 11 and Windows Server 2012 branches (see vendor ranges) and are fixed in specific builds such as 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725 and later equivalents. The vulnerability is a heap-based buffer overflow (CWE-122) exploitable over the network without credentials or user interaction, according to the supplied CVSS vector. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 10 Version 1607 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1607 10.x | 10.0.14393.0 – before 10.0.14393.9512 | 10.0.14393.9512 |
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9245 | 10.0.17763.9245 |
| Windows 10 Version 21H2 10.x | 10.0.19044.0 – before 10.0.19044.7725 | 10.0.19044.7725 |
| Windows 10 Version 22H2 10.x | 10.0.19045.0 – before 10.0.19045.7725 | 10.0.19045.7725 |
| Windows 11 version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 24H2 10.x | 10.0.26100.0 – before 10.0.26100.9445 | 10.0.26100.9445 |
| Windows 11 Version 25H2 10.x | 10.0.26200.0 – before 10.0.26200.9445 | 10.0.26200.9445 |
| Windows 11 version 26H1 10.x | 10.0.28000.0 – before 10.0.28000.2954 | 10.0.28000.2954 |
| Windows Server 2012 6.x | 6.2.9200.0 – before 6.2.9200.26349 | 6.2.9200.26349 |
Is CVE-2026-69491 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-69491
- Identify affected builds using the vendor's listed build ranges and inventory tools.
- Install the fixed builds listed by the vendor (for example 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725 or later builds shown in the vendor data).
- If immediate patching is not possible, restrict network exposure of vulnerable hosts and block untrusted multimedia content sources.
- Monitor endpoints for signs of compromise and review network logs for suspicious DirectMusic or multimedia traffic.
Frequently asked questions
Is CVE-2026-69491 being actively exploited?
There are no public reports of exploitation as of 2026-09-29.
Which Windows versions are affected by CVE-2026-69491?
Multiple Windows 10 and Windows 11 branches and Windows Server 2012 builds are affected; the vendor provided exact build ranges for each branch (for example 10.0.14393.0 – before 10.0.14393.9512).
Is there a patch for CVE-2026-69491?
Yes. Microsoft published fixed builds for the affected branches, for example 10.0.14393.9512, 10.0.17763.9245 and 10.0.19044.7725; install the appropriate fixed build for your branch.
Does CVE-2026-69491 require authentication?
No. The vulnerability can be exploited without authentication or user interaction according to the provided CVSS vector.
References
- nvd.nist.gov/vuln/detail/CVE-2026-69491
- cve.org/CVERecord?id=CVE-2026-69491
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69491
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026