• PATCH AVAILABLE

CVE-2026-69496: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An unauthenticated remote attacker can execute arbitrary code in the Windows Compressed Folder component, allowing full control of affected systems. CVE-2026-69496 affects multiple Windows branches including Windows 10 Version 1607, 1809, 21H2, 22H2, several Windows 11 releases (23H2, 24H2, 25H2, 26H1) and Windows Server 2012; specific affected builds are listed by Microsoft. The flaw requires network access and no user interaction or authentication to trigger.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-122
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is high-severity, remotely triggerable code execution with no authentication required, so prioritize patching to the fixed builds Microsoft published immediately.

What is CVE-2026-69496?

An unauthenticated remote attacker can execute arbitrary code in the Windows Compressed Folder component, allowing full control of affected systems. CVE-2026-69496 affects multiple Windows branches including Windows 10 Version 1607, 1809, 21H2, 22H2, several Windows 11 releases (23H2, 24H2, 25H2, 26H1) and Windows Server 2012; specific affected builds are listed by Microsoft. The flaw requires network access and no user interaction or authentication to trigger. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349

Is CVE-2026-69496 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-69496

  1. Install the Microsoft updates that contain the fixes (examples: 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954, 6.2.9200.26349).
  2. If you cannot patch immediately, restrict network exposure of file-sharing and archive-handling services and block access to affected hosts from untrusted networks.
  3. Monitor endpoint logs for abnormal process creation, crashes in compressed folder handlers, and signs of remote code execution.
  4. Follow Microsoft's advisory and deploy vendor-recommended mitigations and detection guidance.

Frequently asked questions

Is CVE-2026-69496 being actively exploited?

There are no public reports of exploitation as of 2026-09-29.

Which Windows 10 Version 1607 versions are affected by CVE-2026-69496?

Windows 10 Version 1607 builds from 10.0.14393.0 up to but not including 10.0.14393.9512 are affected.

Is there a patch for CVE-2026-69496?

Yes. Microsoft published fixes; affected branches have fixed builds such as 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725 and others listed in the vendor bulletin.

Does CVE-2026-69496 require authentication?

No. The vulnerability can be triggered by an attacker over the network without authentication.

References