• PATCH AVAILABLE

CVE-2026-69819: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An unauthenticated remote attacker can execute arbitrary code on affected Windows systems via an out-of-bounds write in the RPC Runtime; this is tracked as CVE-2026-69819. Affected releases include Windows 10 Version 1607 (10.0.14393.0 through before 10.0.14393.9512), Windows 10 Version 1809, 21H2, 22H2, multiple Windows 11 branches (including 23H2, 24H2, 25H2, 26H1) and Windows Server 2012 in the ranges listed by the vendor. The flaw is remotely reachable over the network and does not require authentication or user interaction.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-787
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a network-reachable, unauthenticated remote code execution (no login required), so prioritise installing vendor updates or blocking RPC exposure from untrusted networks immediately.

What is CVE-2026-69819?

An unauthenticated remote attacker can execute arbitrary code on affected Windows systems via an out-of-bounds write in the RPC Runtime; this is tracked as CVE-2026-69819. Affected releases include Windows 10 Version 1607 (10.0.14393.0 through before 10.0.14393.9512), Windows 10 Version 1809, 21H2, 22H2, multiple Windows 11 branches (including 23H2, 24H2, 25H2, 26H1) and Windows Server 2012 in the ranges listed by the vendor. The flaw is remotely reachable over the network and does not require authentication or user interaction. The weakness is classified as CWE-787 (Out-of-bounds Write).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349

Is CVE-2026-69819 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-69819

  1. Apply Microsoft updates that move affected builds to the fixed builds (for example 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954, 6.2.9200.26349).
  2. If you cannot patch immediately, restrict RPC/remote management ports to trusted networks and block access from the internet.
  3. Monitor network and endpoint logs for unusual RPC connections and signs of code execution, and apply vendor guidance.
  4. Test and roll out patches promptly following your change-control procedures.

Frequently asked questions

Is CVE-2026-69819 being actively exploited?

No public reports of active exploitation of CVE-2026-69819 were available as of 2026-09-29.

Which Windows 10 Version 1607 versions are affected by CVE-2026-69819?

Windows 10 Version 1607 systems with build 10.0.14393.0 up to but not including 10.0.14393.9512 are affected; the fixed build is 10.0.14393.9512.

Is there a patch for CVE-2026-69819?

Yes. Microsoft published fixes; affected branches have specific fixed builds such as 10.0.14393.9512 (1607), 10.0.17763.9245 (1809), 10.0.19044.7725 (21H2), 10.0.19045.7725 (22H2), and others listed by the vendor.

Does CVE-2026-69819 require authentication?

No. The vulnerability in the RPC Runtime can be exploited remotely without authentication or user interaction on affected Windows releases.

References