• PATCH AVAILABLE

CVE-2026-69586: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An unauthenticated attacker can remotely execute arbitrary code in Windows PDF handling via an integer overflow (CVE-2026-69586). Affected builds include multiple Windows 10, Windows 11, and Windows Server 2016 branches: for example Windows 10 Version 1607 builds 10.0.14393.0 through before 10.0.14393.9512, Windows 10 Version 1809 through before 10.0.17763.9245, and several later branches; fixed builds are provided for each affected branch. The flaw requires network access and no user interaction or valid credentials.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-190
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Patch urgently: this is an unauthenticated remote code execution vulnerability that can be reached over the network, so apply the vendor updates for the fixed builds immediately or block exposure to untrusted networks.

What is CVE-2026-69586?

An unauthenticated attacker can remotely execute arbitrary code in Windows PDF handling via an integer overflow (CVE-2026-69586). Affected builds include multiple Windows 10, Windows 11, and Windows Server 2016 branches: for example Windows 10 Version 1607 builds 10.0.14393.0 through before 10.0.14393.9512, Windows 10 Version 1809 through before 10.0.17763.9245, and several later branches; fixed builds are provided for each affected branch. The flaw requires network access and no user interaction or valid credentials.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2016 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512

Is CVE-2026-69586 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-69586

  1. Install the Microsoft updates that deliver the fixed builds (examples include 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725 and the corresponding fixed versions for later branches).
  2. If you cannot patch immediately, restrict network exposure of affected systems and block untrusted PDF sources at gateways.
  3. Enable and review endpoint and network detection for suspicious PDF handling or process launches.
  4. Follow Microsoft's guidance for applying updates and reboot affected hosts as required.

Frequently asked questions

Is CVE-2026-69586 being actively exploited?

There are no public reports of active exploitation of CVE-2026-69586 as of 2026-09-29.

Which Windows 10 Version 1607 versions are affected by CVE-2026-69586?

Windows 10 Version 1607 builds from 10.0.14393.0 up to but not including 10.0.14393.9512 are affected; 10.0.14393.9512 is listed as the fixed build for that branch.

Is there a patch for CVE-2026-69586?

Yes. Microsoft published fixes; each affected branch lists a fixed build (for example 10.0.14393.9512, 10.0.17763.9245, and other branch-specific fixed builds).

Does CVE-2026-69586 require authentication?

No. CVE-2026-69586 can be exploited without authentication and does not require user interaction.

References