DIRAS TAKE
Urgent: this is an unauthenticated remote code execution vulnerability that can be reached over the network, so prioritize patching systems exposed to untrusted networks or internet-facing NFS services.
What is CVE-2026-69595?
An unauthenticated remote attacker can execute arbitrary code on Windows Server via a use-after-free vulnerability in the Services for NFS ONCRPC XDR driver (CVE-2026-69595). Affected releases include Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025 branches up to—but not including—the fixed builds listed by Microsoft; the exploit requires network access and does not require valid credentials. The weakness is classified as CWE-416 (Use After Free).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows Server 2012 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows Server 2012 6.x | 6.2.9200.0 – before 6.2.9200.26349 | 6.2.9200.26349 |
| Windows Server 2012 (Server Core installation) 6.x | 6.2.9200.0 – before 6.2.9200.26349 | 6.2.9200.26349 |
| Windows Server 2012 R2 6.x | 6.3.9600.0 – before 6.3.9600.23398 | 6.3.9600.23398 |
| Windows Server 2012 R2 (Server Core installation) 6.x | 6.3.9600.0 – before 6.3.9600.23398 | 6.3.9600.23398 |
| Windows Server 2016 10.x | 10.0.14393.0 – before 10.0.14393.9512 | 10.0.14393.9512 |
| Windows Server 2016 (Server Core installation) 10.x | 10.0.14393.0 – before 10.0.14393.9512 | 10.0.14393.9512 |
| Windows Server 2019 10.x | 10.0.17763.0 – before 10.0.17763.9245 | 10.0.17763.9245 |
| Windows Server 2019 (Server Core installation) 10.x | 10.0.17763.0 – before 10.0.17763.9245 | 10.0.17763.9245 |
| Windows Server 2022 10.x | 10.0.20348.0 – before 10.0.20348.5622 | 10.0.20348.5622 |
| Windows Server 2025 10.x | 10.0.26100.0 – before 10.0.26100.33438 | 10.0.26100.33438 |
Is CVE-2026-69595 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-69595
- Apply the vendor updates that include the fixes: install fixed builds 6.2.9200.26349, 6.3.9600.23398, 10.0.14393.9512, 10.0.17763.9245, 10.0.20348.5622 or 10.0.26100.33438 as appropriate for your branch.
- If you cannot patch immediately, restrict network exposure to affected Windows Server hosts and block access to NFS/ONCRPC services from untrusted networks.
- Monitor syslogs and EDR telemetry for unusual process creation or remote connections to NFS-related services.
- Follow Microsoft's advisory and guidance for additional mitigation steps and verification procedures.
Frequently asked questions
Is CVE-2026-69595 being actively exploited?
There are no public reports of active exploitation of CVE-2026-69595 as of 2026-09-29.
Which Windows Server versions are affected by CVE-2026-69595?
Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025 branches are listed as affected in the vendor data, with fixed builds provided for each branch.
Is there a patch for CVE-2026-69595?
Yes. Microsoft published fixes; affected branches have specific fixed builds such as 6.2.9200.26349, 6.3.9600.23398, 10.0.14393.9512, 10.0.17763.9245, 10.0.20348.5622 and 10.0.26100.33438.
Does CVE-2026-69595 require authentication?
No. The vulnerability can be exploited by an unauthorized attacker over the network and does not require valid credentials.
References
- nvd.nist.gov/vuln/detail/CVE-2026-69595
- cve.org/CVERecord?id=CVE-2026-69595
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69595
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026