• PATCH AVAILABLE

CVE-2026-70296: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An unauthenticated attacker can execute arbitrary code over a network against Windows systems because of an out-of-bounds write in the Windows Imaging Component; this is tracked as CVE-2026-70296. The flaw affects multiple Windows 10 and Windows 11 branches and Windows Server 2012 builds (see affected ranges) and requires only network access — no user interaction or valid account is needed. Microsoft has released fixed builds for the listed branches; apply updates to move to the fixed builds to remediate the issue.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-787
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent — this is an unauthenticated, remotely reachable code-execution flaw in a common Windows component; apply Microsoft’s fixes for the affected builds immediately and limit network exposure of vulnerable hosts.

What is CVE-2026-70296?

An unauthenticated attacker can execute arbitrary code over a network against Windows systems because of an out-of-bounds write in the Windows Imaging Component; this is tracked as CVE-2026-70296. The flaw affects multiple Windows 10 and Windows 11 branches and Windows Server 2012 builds (see affected ranges) and requires only network access — no user interaction or valid account is needed. Microsoft has released fixed builds for the listed branches; apply updates to move to the fixed builds to remediate the issue. The weakness is classified as CWE-787 (Out-of-bounds Write).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349

Is CVE-2026-70296 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-70296

  1. Install Microsoft’s updates that bring systems to the fixed builds (for example 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725).
  2. Identify and patch all affected Windows 10/11 and Windows Server 2012 systems listed in the vendor advisory.
  3. Restrict network exposure of systems that cannot be patched immediately (block untrusted access to services that process images).
  4. Monitor host and network logs for unusual activity and follow Microsoft’s guidance for post-patch validation.

Frequently asked questions

Is CVE-2026-70296 being actively exploited?

There are no public reports of exploitation of CVE-2026-70296 as of 2026-09-29.

Which Windows 10 Version 1607 versions are affected by CVE-2026-70296?

Windows 10 Version 1607 builds from 10.0.14393.0 up to before 10.0.14393.9512 are affected; the issue is fixed in build 10.0.14393.9512.

Is there a patch for CVE-2026-70296?

Yes. Microsoft published updates that include fixed builds such as 10.0.14393.9512 (and corresponding fixed builds for other affected branches); apply Microsoft’s updates for your branch.

Does CVE-2026-70296 require authentication?

No. CVE-2026-70296 can be exploited without authentication and only requires network access to a vulnerable Windows Imaging Component instance.

References