• PATCH AVAILABLE

CVE-2026-69579: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An unauthenticated attacker can execute code remotely against Windows Message Queuing due to a use-after-free vulnerability (CWE-416) tracked as CVE-2026-69579. Affected branches include Windows 10 Version 1607, 1809, 21H2, 22H2, multiple Windows 11 branches (23H2, 24H2, 25H2, 26H1) and Windows Server 2012; vendors published fixed build numbers for each affected branch. The vulnerability is exploitable over a network without user interaction or credentials and allows arbitrary code execution on vulnerable hosts.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-416
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgently prioritize patching because this is an unauthenticated, network-accessible remote code execution (CVSS 9.8) that lets attackers run code without a login. Apply the supplied fixed builds to exposed systems immediately.

What is CVE-2026-69579?

An unauthenticated attacker can execute code remotely against Windows Message Queuing due to a use-after-free vulnerability (CWE-416) tracked as CVE-2026-69579. Affected branches include Windows 10 Version 1607, 1809, 21H2, 22H2, multiple Windows 11 branches (23H2, 24H2, 25H2, 26H1) and Windows Server 2012; vendors published fixed build numbers for each affected branch. The vulnerability is exploitable over a network without user interaction or credentials and allows arbitrary code execution on vulnerable hosts. The weakness is classified as CWE-416 (Use After Free).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349

Is CVE-2026-69579 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-69579

  1. Install Microsoft updates that provide the fixed builds listed for each affected branch (for example 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954 and 6.2.9200.26349).
  2. If immediate patching is not possible, restrict network exposure of systems running Windows Message Queuing to trusted hosts and networks.
  3. Monitor endpoint and network logs for unusual process creation, remote service access, and indicators of compromise related to Message Queuing.
  4. Follow Microsoft's guidance for deployment and post-patch validation to ensure updates applied correctly.

Frequently asked questions

Is CVE-2026-69579 being actively exploited?

There are no public reports of exploitation of CVE-2026-69579 as of 2026-09-29.

Which Windows versions are affected by CVE-2026-69579?

Windows Message Queuing on multiple branches is affected, including Windows 10 Version 1607, 1809, 21H2, 22H2, several Windows 11 branches (23H2, 24H2, 25H2, 26H1) and Windows Server 2012; fixed build numbers are published for each branch.

Is there a patch for CVE-2026-69579?

Yes, Microsoft published updates; install the fixed builds referenced for each affected branch to remediate the vulnerability.

Does CVE-2026-69579 require authentication?

No, the vulnerability can be exploited without authentication and without user interaction against vulnerable Windows Message Queuing implementations.

References