DIRAS TAKE
Urgent: this is a network-reachable, unauthenticated remote code execution (no login required), so prioritise installing vendor updates or blocking RPC exposure from untrusted networks immediately.
What is CVE-2026-69819?
An unauthenticated remote attacker can execute arbitrary code on affected Windows systems via an out-of-bounds write in the RPC Runtime; this is tracked as CVE-2026-69819. Affected releases include Windows 10 Version 1607 (10.0.14393.0 through before 10.0.14393.9512), Windows 10 Version 1809, 21H2, 22H2, multiple Windows 11 branches (including 23H2, 24H2, 25H2, 26H1) and Windows Server 2012 in the ranges listed by the vendor. The flaw is remotely reachable over the network and does not require authentication or user interaction. The weakness is classified as CWE-787 (Out-of-bounds Write).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 10 Version 1607 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1607 10.x | 10.0.14393.0 – before 10.0.14393.9512 | 10.0.14393.9512 |
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9245 | 10.0.17763.9245 |
| Windows 10 Version 21H2 10.x | 10.0.19044.0 – before 10.0.19044.7725 | 10.0.19044.7725 |
| Windows 10 Version 22H2 10.x | 10.0.19045.0 – before 10.0.19045.7725 | 10.0.19045.7725 |
| Windows 11 version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 24H2 10.x | 10.0.26100.0 – before 10.0.26100.9445 | 10.0.26100.9445 |
| Windows 11 Version 25H2 10.x | 10.0.26200.0 – before 10.0.26200.9445 | 10.0.26200.9445 |
| Windows 11 version 26H1 10.x | 10.0.28000.0 – before 10.0.28000.2954 | 10.0.28000.2954 |
| Windows Server 2012 6.x | 6.2.9200.0 – before 6.2.9200.26349 | 6.2.9200.26349 |
Is CVE-2026-69819 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-69819
- Apply Microsoft updates that move affected builds to the fixed builds (for example 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954, 6.2.9200.26349).
- If you cannot patch immediately, restrict RPC/remote management ports to trusted networks and block access from the internet.
- Monitor network and endpoint logs for unusual RPC connections and signs of code execution, and apply vendor guidance.
- Test and roll out patches promptly following your change-control procedures.
Frequently asked questions
Is CVE-2026-69819 being actively exploited?
No public reports of active exploitation of CVE-2026-69819 were available as of 2026-09-29.
Which Windows 10 Version 1607 versions are affected by CVE-2026-69819?
Windows 10 Version 1607 systems with build 10.0.14393.0 up to but not including 10.0.14393.9512 are affected; the fixed build is 10.0.14393.9512.
Is there a patch for CVE-2026-69819?
Yes. Microsoft published fixes; affected branches have specific fixed builds such as 10.0.14393.9512 (1607), 10.0.17763.9245 (1809), 10.0.19044.7725 (21H2), 10.0.19045.7725 (22H2), and others listed by the vendor.
Does CVE-2026-69819 require authentication?
No. The vulnerability in the RPC Runtime can be exploited remotely without authentication or user interaction on affected Windows releases.
References
- nvd.nist.gov/vuln/detail/CVE-2026-69819
- cve.org/CVERecord?id=CVE-2026-69819
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69819
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026