DIRAS TAKE
Urgent: this flaw permits remote code execution without authentication, so prioritize patching or isolation because an unauthenticated network attacker can reach vulnerable systems.
What is CVE-2026-69910?
An attacker can execute arbitrary code on affected Microsoft Windows installations without authentication and over a network. CVE-2026-69910 is a stack-based buffer overflow (CWE-121) that allows remote code execution; it affects multiple Windows branches including Windows 10 Version 1607 (builds 10.0.14393.0 through before 10.0.14393.9512) and later Windows 10/11 and Server builds listed in vendor advisories. Exploitation requires network access and does not require user interaction or valid credentials.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 10 Version 1607 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1607 10.x | 10.0.14393.0 – before 10.0.14393.9512 | 10.0.14393.9512 |
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9245 | 10.0.17763.9245 |
| Windows 10 Version 21H2 10.x | 10.0.19044.0 – before 10.0.19044.7725 | 10.0.19044.7725 |
| Windows 10 Version 22H2 10.x | 10.0.19045.0 – before 10.0.19045.7725 | 10.0.19045.7725 |
| Windows 11 version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 24H2 10.x | 10.0.26100.0 – before 10.0.26100.9445 | 10.0.26100.9445 |
| Windows 11 Version 25H2 10.x | 10.0.26200.0 – before 10.0.26200.9445 | 10.0.26200.9445 |
| Windows 11 version 26H1 10.x | 10.0.28000.0 – before 10.0.28000.2954 | 10.0.28000.2954 |
| Windows Server 2016 10.x | 10.0.14393.0 – before 10.0.14393.9512 | 10.0.14393.9512 |
Is CVE-2026-69910 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-69910
- Apply the vendor updates that include the fixes: update affected systems to the fixed builds (examples: 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954).
- Restrict network exposure for Hyper-V and other Windows services by limiting allowed inbound connections and blocking untrusted networks.
- Monitor endpoints and network logs for suspicious activity including unexpected process creation and anomalous remote connections to Hyper-V or related services.
- Follow Microsoft guidance and deploy security updates from your software management tools as soon as possible.
Frequently asked questions
Is CVE-2026-69910 being actively exploited?
There are no public reports of exploitation of CVE-2026-69910 as of 2026-09-29.
Which Windows 10 Version 1607 versions are affected by CVE-2026-69910?
Windows 10 Version 1607 builds from 10.0.14393.0 up to but not including 10.0.14393.9512 are listed as affected by CVE-2026-69910.
Is there a patch for CVE-2026-69910?
Yes. Microsoft published fixes; vulnerable branches are fixed at builds such as 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725 and later builds listed by the vendor.
Does CVE-2026-69910 require authentication?
No. CVE-2026-69910 allows remote code execution without authentication on affected Windows builds and requires only network access.
References
- nvd.nist.gov/vuln/detail/CVE-2026-69910
- cve.org/CVERecord?id=CVE-2026-69910
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69910
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026