DIRAS TAKE
Urgent: this is a remotely exploitable, pre-auth RCE with a critical 9.8 CVSS and vendor fixes available — prioritize installing the listed updates or isolating RRAS from untrusted networks.
What is CVE-2026-69590?
Remote attackers can execute arbitrary code on Windows Routing and Remote Access Service (RRAS) implementations, allowing unauthorized control of affected systems; this issue is tracked as CVE-2026-69590. A range of Windows builds are affected, including Windows 10 branches (1607, 1809, 21H2, 22H2), multiple Windows 11 branches (including 23H2, 24H2, 25H2, 26H1) and Windows Server 2012, with fixed builds published for each branch. The flaw can be exploited remotely over the network and requires no privileges or user interaction. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 10 Version 1607 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1607 10.x | 10.0.14393.0 – before 10.0.14393.9512 | 10.0.14393.9512 |
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9245 | 10.0.17763.9245 |
| Windows 10 Version 21H2 10.x | 10.0.19044.0 – before 10.0.19044.7725 | 10.0.19044.7725 |
| Windows 10 Version 22H2 10.x | 10.0.19045.0 – before 10.0.19045.7725 | 10.0.19045.7725 |
| Windows 11 version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 24H2 10.x | 10.0.26100.0 – before 10.0.26100.9445 | 10.0.26100.9445 |
| Windows 11 Version 25H2 10.x | 10.0.26200.0 – before 10.0.26200.9445 | 10.0.26200.9445 |
| Windows 11 version 26H1 10.x | 10.0.28000.0 – before 10.0.28000.2954 | 10.0.28000.2954 |
| Windows Server 2012 6.x | 6.2.9200.0 – before 6.2.9200.26349 | 6.2.9200.26349 |
Is CVE-2026-69590 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-69590
- Apply the Microsoft security updates that move affected branches to the fixed builds (for example: 10.0.14393.9512; 10.0.17763.9245; 10.0.19044.7725; 10.0.19045.7725; 10.0.22631.7582; 10.0.26100.9445; 10.0.26200.9445; 10.0.28000.2954; 6.2.9200.26349).
- If you cannot patch immediately, restrict network exposure of RRAS and block access from untrusted networks.
- Monitor endpoint and network logs for suspicious activity targeting RRAS and for successful remote code execution indicators.
- Follow Microsoft guidance for deploying the updates and validating system build numbers after remediation.
Frequently asked questions
Is CVE-2026-69590 being actively exploited?
There are no public reports of exploitation of CVE-2026-69590 as of 2026-09-29.
Which Windows versions are affected by CVE-2026-69590?
Multiple Windows branches are affected, including Windows 10 (1607, 1809, 21H2, 22H2), several Windows 11 branches (23H2, 24H2, 25H2, 26H1) and Windows Server 2012, with specific build ranges identified by Microsoft.
Is there a patch for CVE-2026-69590?
Yes, Microsoft published fixes for each affected branch; affected builds are corrected in the fixed build numbers listed by the vendor for each branch.
Does CVE-2026-69590 require authentication?
No, the vulnerability can be exploited remotely without authentication or user interaction against RRAS on affected Windows builds.
References
- nvd.nist.gov/vuln/detail/CVE-2026-69590
- cve.org/CVERecord?id=CVE-2026-69590
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69590
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026