• PATCH AVAILABLE

CVE-2026-69824: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An unauthenticated attacker can execute arbitrary code remotely against Microsoft Windows 10 Version 1607 and several other Windows branches via an integer underflow in the Microsoft Standard XPS component (CVE-2026-69824). Affected builds span multiple Windows 10 and Windows 11 branches and Windows Server 2012; fixed builds are listed by Microsoft for each affected branch. Exploitation requires network access to the vulnerable component and does not require user interaction or valid credentials.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-191
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is unauthenticated remote code execution against an internet-reachable component, so prioritize installing the vendor fixes listed for each affected build or otherwise block access to the vulnerable service.

What is CVE-2026-69824?

An unauthenticated attacker can execute arbitrary code remotely against Microsoft Windows 10 Version 1607 and several other Windows branches via an integer underflow in the Microsoft Standard XPS component (CVE-2026-69824). Affected builds span multiple Windows 10 and Windows 11 branches and Windows Server 2012; fixed builds are listed by Microsoft for each affected branch. Exploitation requires network access to the vulnerable component and does not require user interaction or valid credentials.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349

Is CVE-2026-69824 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-69824

  1. Apply Microsoft updates that move affected systems to the fixed builds (for example 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725 and other fixed builds listed by Microsoft).
  2. If immediate patching is not possible, restrict network exposure to the affected component and block access from untrusted networks.
  3. Monitor endpoints and network logs for anomalous activity and signs of code execution targeting the Microsoft Standard XPS component.
  4. Follow Microsoft's guidance and deploy the vendor-recommended update rollout for your environment.

Frequently asked questions

Is CVE-2026-69824 being actively exploited?

There are no public reports of exploitation of CVE-2026-69824 as of 2026-09-29.

Which Windows 10 Version 1607 versions are affected by CVE-2026-69824?

Windows 10 Version 1607 builds from 10.0.14393.0 up to but not including 10.0.14393.9512 are affected.

Is there a patch for CVE-2026-69824?

Yes. Microsoft published fixed builds for each affected branch, for example 10.0.14393.9512 for Windows 10 Version 1607 and corresponding fixed builds for other branches.

Does CVE-2026-69824 require authentication?

No. The vulnerability can be exploited by an unauthenticated attacker over the network against the Microsoft Standard XPS component.

References