• PATCH AVAILABLE

CVE-2026-69768: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An unauthenticated attacker can remotely execute code against Windows systems by exploiting a heap-based buffer overflow in the RNDIS component; see CVE-2026-69768. Affected builds include multiple Windows 10 and Windows 11 branches and Windows Server 2012 ranges (examples: 10.0.14393.0 through before 10.0.14393.9512, 10.0.17763.0 through before 10.0.17763.9245, and others listed by Microsoft). Successful exploitation requires only network access to the vulnerable RNDIS service and does not require credentials or user interaction.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-122
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this flaw allows remote code execution without authentication, so prioritize installing the vendor fixes for the affected builds immediately to eliminate remote attack paths.

What is CVE-2026-69768?

An unauthenticated attacker can remotely execute code against Windows systems by exploiting a heap-based buffer overflow in the RNDIS component; see CVE-2026-69768. Affected builds include multiple Windows 10 and Windows 11 branches and Windows Server 2012 ranges (examples: 10.0.14393.0 through before 10.0.14393.9512, 10.0.17763.0 through before 10.0.17763.9245, and others listed by Microsoft). Successful exploitation requires only network access to the vulnerable RNDIS service and does not require credentials or user interaction. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349

Is CVE-2026-69768 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-69768

  1. Install Microsoft updates that move affected systems to the fixed builds (for example, 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954, and 6.2.9200.26349).
  2. If you cannot patch immediately, restrict network exposure to systems offering RNDIS services and block access from untrusted networks.
  3. Monitor network and host logs for unusual RNDIS activity and signs of remote code execution, and follow Microsoft's guidance and advisories for this CVE.

Frequently asked questions

Is CVE-2026-69768 being actively exploited?

There are no public reports of active exploitation of CVE-2026-69768 as of 2026-09-29.

Which Windows 10 Version 1607 versions are affected by CVE-2026-69768?

Windows 10 Version 1607 builds from 10.0.14393.0 up to before 10.0.14393.9512 are listed as affected by CVE-2026-69768.

Is there a patch for CVE-2026-69768?

Yes. Microsoft published updates that fix the issue; affected branches have fixed builds such as 10.0.14393.9512 and the other fixed build numbers listed by Microsoft.

Does CVE-2026-69768 require authentication?

No. The vulnerability in Windows RNDIS can be triggered by an unauthenticated remote attacker and does not require user interaction.

References