• PATCH AVAILABLE

CVE-2026-69715: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An unauthenticated attacker can execute arbitrary code on affected Windows systems by sending crafted network data that triggers an out-of-bounds read in DirectShow. CVE-2026-69715 affects multiple Windows 10, Windows 11 and Windows Server 2012 builds; vulnerable ranges include Windows 10 Version 1607 (10.0.14393.0 before 10.0.14393.9512), 1809, 21H2, 22H2 and several Windows 11 and Server releases as listed in vendor advisories. No authentication or user interaction is required; network access to the vulnerable component is sufficient.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-125
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a pre-auth, network-triggered remote code execution (CVSS 9.8) that requires no login or user action, so prioritize applying the provided security updates for the fixed builds.

What is CVE-2026-69715?

An unauthenticated attacker can execute arbitrary code on affected Windows systems by sending crafted network data that triggers an out-of-bounds read in DirectShow. CVE-2026-69715 affects multiple Windows 10, Windows 11 and Windows Server 2012 builds; vulnerable ranges include Windows 10 Version 1607 (10.0.14393.0 before 10.0.14393.9512), 1809, 21H2, 22H2 and several Windows 11 and Server releases as listed in vendor advisories. No authentication or user interaction is required; network access to the vulnerable component is sufficient.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349

Is CVE-2026-69715 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-69715

  1. Install the vendor updates that include the fixed builds (for example 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954, and 6.2.9200.26349).
  2. If immediate patching is not possible, restrict network exposure to DirectShow-related services and block untrusted inbound traffic at network edges.
  3. Monitor affected hosts for unusual process activity and network connections and review IDS/IPS logs for exploitation indicators.
  4. Follow Microsoft guidance for deployment and validate updates applied successfully.

Frequently asked questions

Is CVE-2026-69715 being actively exploited?

No public reports indicate active exploitation of CVE-2026-69715 as of 2026-09-29; it is not listed in the CISA KEV catalog and no public exploit code has been published.

Which Windows versions are affected by CVE-2026-69715?

Multiple Windows 10 and Windows 11 branches and Windows Server 2012 builds are affected; vulnerable ranges are listed by build number in vendor advisories (see affected builds such as 10.0.14393.0–before 10.0.14393.9512 and others).

Is there a patch for CVE-2026-69715?

Yes. Microsoft published updates that fix the issue; fixed build numbers include 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954, and 6.2.9200.26349.

Does CVE-2026-69715 require authentication?

No. CVE-2026-69715 can be triggered without authentication or user interaction; an attacker only needs network access to the vulnerable component.

References