• PATCH AVAILABLE

CVE-2026-69493: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An unauthenticated attacker can execute code on Windows systems by exploiting an out-of-bounds read in the Windows Event Logging Service; see CVE-2026-69493. Microsoft lists multiple affected branches — Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (several releases) and Windows Server 2012 — with specific build ranges affected and fixed builds provided. The flaw requires only network access to the vulnerable service; no authentication or user interaction is needed.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-125
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Treat this as high priority: the bug allows unauthenticated remote code execution over the network, so apply Microsoft's fixed builds or mitigations promptly to internet-exposed and critical hosts.

What is CVE-2026-69493?

An unauthenticated attacker can execute code on Windows systems by exploiting an out-of-bounds read in the Windows Event Logging Service; see CVE-2026-69493. Microsoft lists multiple affected branches — Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (several releases) and Windows Server 2012 — with specific build ranges affected and fixed builds provided. The flaw requires only network access to the vulnerable service; no authentication or user interaction is needed.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349

Is CVE-2026-69493 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-69493

  1. Apply Microsoft's updates to the fixed builds (for example 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954, 6.2.9200.26349).
  2. If you cannot patch immediately, restrict network exposure to the Event Logging Service and block unnecessary inbound access.
  3. Monitor logs and endpoints for unusual process creation or signs of exploit attempts against the Event Logging Service.
  4. Follow Microsoft's guidance and deploy cumulative updates from Windows Update or your management tooling as soon as possible.

Frequently asked questions

Is CVE-2026-69493 being actively exploited?

There are no public reports of active exploitation of CVE-2026-69493 as of 2026-09-29.

Which Windows versions are affected by CVE-2026-69493?

The vulnerability affects multiple Windows branches including Windows 10 (1607, 1809, 21H2, 22H2), several Windows 11 releases and Windows Server 2012 within the specific build ranges Microsoft published.

Is there a patch for CVE-2026-69493?

Yes. Microsoft published fixed builds for each affected branch; install the listed fixed build for your branch (examples include 10.0.14393.9512 and 10.0.17763.9245).

Does CVE-2026-69493 require authentication?

No. The flaw in the Windows Event Logging Service can be exploited without authentication and does not require user interaction.

References