DIRAS TAKE
Urgent — this is an unauthenticated, remotely reachable code-execution flaw in a common Windows component; apply Microsoft’s fixes for the affected builds immediately and limit network exposure of vulnerable hosts.
What is CVE-2026-70296?
An unauthenticated attacker can execute arbitrary code over a network against Windows systems because of an out-of-bounds write in the Windows Imaging Component; this is tracked as CVE-2026-70296. The flaw affects multiple Windows 10 and Windows 11 branches and Windows Server 2012 builds (see affected ranges) and requires only network access — no user interaction or valid account is needed. Microsoft has released fixed builds for the listed branches; apply updates to move to the fixed builds to remediate the issue. The weakness is classified as CWE-787 (Out-of-bounds Write).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 10 Version 1607 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1607 10.x | 10.0.14393.0 – before 10.0.14393.9512 | 10.0.14393.9512 |
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9245 | 10.0.17763.9245 |
| Windows 10 Version 21H2 10.x | 10.0.19044.0 – before 10.0.19044.7725 | 10.0.19044.7725 |
| Windows 10 Version 22H2 10.x | 10.0.19045.0 – before 10.0.19045.7725 | 10.0.19045.7725 |
| Windows 11 version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 24H2 10.x | 10.0.26100.0 – before 10.0.26100.9445 | 10.0.26100.9445 |
| Windows 11 Version 25H2 10.x | 10.0.26200.0 – before 10.0.26200.9445 | 10.0.26200.9445 |
| Windows 11 version 26H1 10.x | 10.0.28000.0 – before 10.0.28000.2954 | 10.0.28000.2954 |
| Windows Server 2012 6.x | 6.2.9200.0 – before 6.2.9200.26349 | 6.2.9200.26349 |
Is CVE-2026-70296 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-70296
- Install Microsoft’s updates that bring systems to the fixed builds (for example 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725).
- Identify and patch all affected Windows 10/11 and Windows Server 2012 systems listed in the vendor advisory.
- Restrict network exposure of systems that cannot be patched immediately (block untrusted access to services that process images).
- Monitor host and network logs for unusual activity and follow Microsoft’s guidance for post-patch validation.
Frequently asked questions
Is CVE-2026-70296 being actively exploited?
There are no public reports of exploitation of CVE-2026-70296 as of 2026-09-29.
Which Windows 10 Version 1607 versions are affected by CVE-2026-70296?
Windows 10 Version 1607 builds from 10.0.14393.0 up to before 10.0.14393.9512 are affected; the issue is fixed in build 10.0.14393.9512.
Is there a patch for CVE-2026-70296?
Yes. Microsoft published updates that include fixed builds such as 10.0.14393.9512 (and corresponding fixed builds for other affected branches); apply Microsoft’s updates for your branch.
Does CVE-2026-70296 require authentication?
No. CVE-2026-70296 can be exploited without authentication and only requires network access to a vulnerable Windows Imaging Component instance.
References
- nvd.nist.gov/vuln/detail/CVE-2026-70296
- cve.org/CVERecord?id=CVE-2026-70296
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70296
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026