• PATCH AVAILABLE

CVE-2026-69525: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An unauthenticated attacker can execute arbitrary code on Windows systems running the affected Remote Desktop Services by sending specially crafted network requests; this is tracked as CVE-2026-69525. The flaw is a use-after-free (CWE-416) and affects multiple Windows 10, Windows 11 and Windows Server branches listed below; an attacker only needs network access to the vulnerable RDP service and does not require credentials or user interaction.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-416
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a critical, pre-auth RDP code execution bug with public fixes available; prioritize installing the vendor updates that move systems to the fixed builds listed below or otherwise block/unexpose RDP from untrusted networks.

What is CVE-2026-69525?

An unauthenticated attacker can execute arbitrary code on Windows systems running the affected Remote Desktop Services by sending specially crafted network requests; this is tracked as CVE-2026-69525. The flaw is a use-after-free (CWE-416) and affects multiple Windows 10, Windows 11 and Windows Server branches listed below; an attacker only needs network access to the vulnerable RDP service and does not require credentials or user interaction. The weakness is classified as CWE-416 (Use After Free).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349

Is CVE-2026-69525 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-69525

  1. Install the security updates that bring affected systems to the fixed builds (examples: 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954, 6.2.9200.26349).
  2. If immediate patching is not possible, restrict network exposure of Remote Desktop Services by blocking RDP at the edge and allowing only trusted management networks.
  3. Enable and enforce Network Level Authentication and strong authentication controls for RDP where applicable.
  4. Monitor RDP logs and network telemetry for unusual connection attempts and exploit-like activity and follow vendor guidance for indicators of compromise.

Frequently asked questions

Is CVE-2026-69525 being actively exploited?

There are no public reports of active exploitation of CVE-2026-69525 as of 2026-09-29.

Which Windows 10 Version 1607 versions are affected by CVE-2026-69525?

Windows systems with builds in the range 10.0.14393.0 through 10.0.14393.9511 are affected; the issue is fixed in 10.0.14393.9512.

Is there a patch for CVE-2026-69525?

Yes, Microsoft published fixes that update affected branches to fixed builds such as 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725 and others listed in the affected data.

Does CVE-2026-69525 require authentication?

No, the vulnerability does not require authentication; an attacker can exploit it over the network without credentials against the Remote Desktop Services on affected Windows builds.

References