• PATCH AVAILABLE

CVE-2026-69829: pre-auth remote code execution in Microsoft Windows 10 Version 1607

Remote, unauthenticated attackers can execute arbitrary code in the Windows Shell via a heap-based buffer overflow (CVE-2026-69829). The flaw affects multiple Windows 10, Windows 11 and Windows Server 2012 branches; affected builds include ranges that are fixed in builds such as 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725 and later fixed builds listed by Microsoft. An attacker only needs network access to trigger the overflow; no user interaction or privileges are required to exploit it.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-122
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a remote, unauthenticated code execution bug with a high-severity rating; prioritize installing the Microsoft fixes for the listed builds because no authentication or user interaction is required to trigger it.

What is CVE-2026-69829?

Remote, unauthenticated attackers can execute arbitrary code in the Windows Shell via a heap-based buffer overflow (CVE-2026-69829). The flaw affects multiple Windows 10, Windows 11 and Windows Server 2012 branches; affected builds include ranges that are fixed in builds such as 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725 and later fixed builds listed by Microsoft. An attacker only needs network access to trigger the overflow; no user interaction or privileges are required to exploit it. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349

Is CVE-2026-69829 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-69829

  1. Install Microsoft updates that provide the fixed builds (for example 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725 and the other fixed builds listed by the vendor).
  2. Verify affected systems' build numbers and update any hosts running affected builds to the corresponding fixed build.
  3. Restrict network exposure of affected hosts by blocking unnecessary inbound services and limiting access from untrusted networks.
  4. Monitor endpoint and network logs for signs of remote code execution and unusual process behavior and follow vendor guidance for remediation.

Frequently asked questions

Is CVE-2026-69829 being actively exploited?

There are no public reports of active exploitation of CVE-2026-69829 as of 2026-09-29.

Which Windows versions are affected by CVE-2026-69829?

Multiple Windows 10 and Windows 11 branches and Windows Server 2012 builds are affected; Microsoft lists specific affected build ranges and provides fixed build numbers such as 10.0.14393.9512, 10.0.17763.9245 and others.

Is there a patch for CVE-2026-69829?

Yes. Microsoft has released updates that include fixed builds; install the corresponding fixed build listed for your Windows branch.

Does CVE-2026-69829 require authentication?

No. The vulnerability can be triggered by an unauthenticated attacker over a network and does not require user interaction or elevated privileges.

References