DIRAS TAKE
Urgently prioritize patching because this is an unauthenticated, network-accessible remote code execution (CVSS 9.8) that lets attackers run code without a login. Apply the supplied fixed builds to exposed systems immediately.
What is CVE-2026-69579?
An unauthenticated attacker can execute code remotely against Windows Message Queuing due to a use-after-free vulnerability (CWE-416) tracked as CVE-2026-69579. Affected branches include Windows 10 Version 1607, 1809, 21H2, 22H2, multiple Windows 11 branches (23H2, 24H2, 25H2, 26H1) and Windows Server 2012; vendors published fixed build numbers for each affected branch. The vulnerability is exploitable over a network without user interaction or credentials and allows arbitrary code execution on vulnerable hosts. The weakness is classified as CWE-416 (Use After Free).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 10 Version 1607 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1607 10.x | 10.0.14393.0 – before 10.0.14393.9512 | 10.0.14393.9512 |
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9245 | 10.0.17763.9245 |
| Windows 10 Version 21H2 10.x | 10.0.19044.0 – before 10.0.19044.7725 | 10.0.19044.7725 |
| Windows 10 Version 22H2 10.x | 10.0.19045.0 – before 10.0.19045.7725 | 10.0.19045.7725 |
| Windows 11 version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 24H2 10.x | 10.0.26100.0 – before 10.0.26100.9445 | 10.0.26100.9445 |
| Windows 11 Version 25H2 10.x | 10.0.26200.0 – before 10.0.26200.9445 | 10.0.26200.9445 |
| Windows 11 version 26H1 10.x | 10.0.28000.0 – before 10.0.28000.2954 | 10.0.28000.2954 |
| Windows Server 2012 6.x | 6.2.9200.0 – before 6.2.9200.26349 | 6.2.9200.26349 |
Is CVE-2026-69579 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-69579
- Install Microsoft updates that provide the fixed builds listed for each affected branch (for example 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954 and 6.2.9200.26349).
- If immediate patching is not possible, restrict network exposure of systems running Windows Message Queuing to trusted hosts and networks.
- Monitor endpoint and network logs for unusual process creation, remote service access, and indicators of compromise related to Message Queuing.
- Follow Microsoft's guidance for deployment and post-patch validation to ensure updates applied correctly.
Frequently asked questions
Is CVE-2026-69579 being actively exploited?
There are no public reports of exploitation of CVE-2026-69579 as of 2026-09-29.
Which Windows versions are affected by CVE-2026-69579?
Windows Message Queuing on multiple branches is affected, including Windows 10 Version 1607, 1809, 21H2, 22H2, several Windows 11 branches (23H2, 24H2, 25H2, 26H1) and Windows Server 2012; fixed build numbers are published for each branch.
Is there a patch for CVE-2026-69579?
Yes, Microsoft published updates; install the fixed builds referenced for each affected branch to remediate the vulnerability.
Does CVE-2026-69579 require authentication?
No, the vulnerability can be exploited without authentication and without user interaction against vulnerable Windows Message Queuing implementations.
References
- nvd.nist.gov/vuln/detail/CVE-2026-69579
- cve.org/CVERecord?id=CVE-2026-69579
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69579
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026