• PATCH AVAILABLE

CVE-2026-69910: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An attacker can execute arbitrary code on affected Microsoft Windows installations without authentication and over a network. CVE-2026-69910 is a stack-based buffer overflow (CWE-121) that allows remote code execution; it affects multiple Windows branches including Windows 10 Version 1607 (builds 10.0.14393.0 through before 10.0.14393.9512) and later Windows 10/11 and Server builds listed in vendor advisories. Exploitation requires network access and does not require user interaction or valid credentials.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-121
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this flaw permits remote code execution without authentication, so prioritize patching or isolation because an unauthenticated network attacker can reach vulnerable systems.

What is CVE-2026-69910?

An attacker can execute arbitrary code on affected Microsoft Windows installations without authentication and over a network. CVE-2026-69910 is a stack-based buffer overflow (CWE-121) that allows remote code execution; it affects multiple Windows branches including Windows 10 Version 1607 (builds 10.0.14393.0 through before 10.0.14393.9512) and later Windows 10/11 and Server builds listed in vendor advisories. Exploitation requires network access and does not require user interaction or valid credentials.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2016 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512

Is CVE-2026-69910 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-69910

  1. Apply the vendor updates that include the fixes: update affected systems to the fixed builds (examples: 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954).
  2. Restrict network exposure for Hyper-V and other Windows services by limiting allowed inbound connections and blocking untrusted networks.
  3. Monitor endpoints and network logs for suspicious activity including unexpected process creation and anomalous remote connections to Hyper-V or related services.
  4. Follow Microsoft guidance and deploy security updates from your software management tools as soon as possible.

Frequently asked questions

Is CVE-2026-69910 being actively exploited?

There are no public reports of exploitation of CVE-2026-69910 as of 2026-09-29.

Which Windows 10 Version 1607 versions are affected by CVE-2026-69910?

Windows 10 Version 1607 builds from 10.0.14393.0 up to but not including 10.0.14393.9512 are listed as affected by CVE-2026-69910.

Is there a patch for CVE-2026-69910?

Yes. Microsoft published fixes; vulnerable branches are fixed at builds such as 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725 and later builds listed by the vendor.

Does CVE-2026-69910 require authentication?

No. CVE-2026-69910 allows remote code execution without authentication on affected Windows builds and requires only network access.

References