• PATCH AVAILABLE

CVE-2026-69769: pre-auth remote code execution in Microsoft Windows 10 Version 1607

Remote attackers can execute arbitrary code on affected Windows systems via a heap-based buffer overflow in the Windows HTTP Print Provider. CVE-2026-69769 affects multiple Windows branches; examples include Windows 10 Version 1607 (10.0.14393.0–before 10.0.14393.9512), Windows 10 Version 1809 (10.0.17763.0–before 10.0.17763.9245), and later listed Windows 11 and Server builds. The flaw requires only network access and no authentication or user interaction to trigger.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-122
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent — this is a remote, unauthenticated code-execution flaw (no login or user click required); prioritize applying the vendor fixes listed for your build immediately.

What is CVE-2026-69769?

Remote attackers can execute arbitrary code on affected Windows systems via a heap-based buffer overflow in the Windows HTTP Print Provider. CVE-2026-69769 affects multiple Windows branches; examples include Windows 10 Version 1607 (10.0.14393.0–before 10.0.14393.9512), Windows 10 Version 1809 (10.0.17763.0–before 10.0.17763.9245), and later listed Windows 11 and Server builds. The flaw requires only network access and no authentication or user interaction to trigger. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349

Is CVE-2026-69769 being exploited?

There are no public reports of active exploitation as of 2026-09-29.

How to fix CVE-2026-69769

  1. Install Microsoft's security update that moves your build to the listed fixed version (for example 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954, or 6.2.9200.26349 as applicable).
  2. If you cannot patch immediately, restrict network exposure to the Windows HTTP Print Provider service and block untrusted network segments.
  3. Monitor logs and IDS for suspicious activity targeting print services and unusual remote code execution indicators.
  4. Apply vendor guidance and test updates in a controlled environment before wide deployment.

Frequently asked questions

Is CVE-2026-69769 being actively exploited?

There are no public reports of active exploitation of CVE-2026-69769 as of 2026-09-29.

Which Windows versions are affected by CVE-2026-69769?

The flaw affects multiple Windows branches including Windows 10 Version 1607, 1809, 21H2, 22H2 and several Windows 11 and Windows Server builds in the version ranges listed in vendor advisories.

Is there a patch for CVE-2026-69769?

Yes. Microsoft released fixes that update vulnerable builds to specific fixed versions such as 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954, and 6.2.9200.26349.

Does CVE-2026-69769 require authentication?

No. The vulnerability can be triggered remotely without authentication or user interaction against the affected Windows print component.

References