• PATCH AVAILABLE

CVE-2026-69595: pre-auth remote code execution in Microsoft Windows Server 2012

An unauthenticated remote attacker can execute arbitrary code on Windows Server via a use-after-free vulnerability in the Services for NFS ONCRPC XDR driver (CVE-2026-69595). Affected releases include Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025 branches up to—but not including—the fixed builds listed by Microsoft; the exploit requires network access and does not require valid credentials.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-416
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is an unauthenticated remote code execution vulnerability that can be reached over the network, so prioritize patching systems exposed to untrusted networks or internet-facing NFS services.

What is CVE-2026-69595?

An unauthenticated remote attacker can execute arbitrary code on Windows Server via a use-after-free vulnerability in the Services for NFS ONCRPC XDR driver (CVE-2026-69595). Affected releases include Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025 branches up to—but not including—the fixed builds listed by Microsoft; the exploit requires network access and does not require valid credentials. The weakness is classified as CWE-416 (Use After Free).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows Server 2012 are affected?

BRANCHAFFECTEDFIXED
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349
Windows Server 2012 (Server Core installation) 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349
Windows Server 2012 R2 6.x6.3.9600.0 – before 6.3.9600.233986.3.9600.23398
Windows Server 2012 R2 (Server Core installation) 6.x6.3.9600.0 – before 6.3.9600.233986.3.9600.23398
Windows Server 2016 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows Server 2016 (Server Core installation) 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows Server 2019 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows Server 2019 (Server Core installation) 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows Server 2022 10.x10.0.20348.0 – before 10.0.20348.562210.0.20348.5622
Windows Server 2025 10.x10.0.26100.0 – before 10.0.26100.3343810.0.26100.33438

Is CVE-2026-69595 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-69595

  1. Apply the vendor updates that include the fixes: install fixed builds 6.2.9200.26349, 6.3.9600.23398, 10.0.14393.9512, 10.0.17763.9245, 10.0.20348.5622 or 10.0.26100.33438 as appropriate for your branch.
  2. If you cannot patch immediately, restrict network exposure to affected Windows Server hosts and block access to NFS/ONCRPC services from untrusted networks.
  3. Monitor syslogs and EDR telemetry for unusual process creation or remote connections to NFS-related services.
  4. Follow Microsoft's advisory and guidance for additional mitigation steps and verification procedures.

Frequently asked questions

Is CVE-2026-69595 being actively exploited?

There are no public reports of active exploitation of CVE-2026-69595 as of 2026-09-29.

Which Windows Server versions are affected by CVE-2026-69595?

Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025 branches are listed as affected in the vendor data, with fixed builds provided for each branch.

Is there a patch for CVE-2026-69595?

Yes. Microsoft published fixes; affected branches have specific fixed builds such as 6.2.9200.26349, 6.3.9600.23398, 10.0.14393.9512, 10.0.17763.9245, 10.0.20348.5622 and 10.0.26100.33438.

Does CVE-2026-69595 require authentication?

No. The vulnerability can be exploited by an unauthorized attacker over the network and does not require valid credentials.

References