• PATCH AVAILABLE

CVE-2026-72950: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An unauthenticated attacker can execute code on Windows systems that run the Routing and Remote Access Service; this is tracked as CVE-2026-72950. The flaw affects multiple Windows 10 and Windows 11 branches and Windows Server 2012 builds — see affected build ranges and fixed builds in the vendor guidance — and an attacker only needs network access to the service (no user interaction or credentials). Successful exploitation could lead to full system compromise on vulnerable builds.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00923
CWE
CWE-122
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: treat this as a high-priority patching task because the vulnerability allows unauthenticated remote code execution over the network. Apply the vendor fixes for affected builds immediately or block RRAS exposure at network perimeters.

What is CVE-2026-72950?

An unauthenticated attacker can execute code on Windows systems that run the Routing and Remote Access Service; this is tracked as CVE-2026-72950. The flaw affects multiple Windows 10 and Windows 11 branches and Windows Server 2012 builds — see affected build ranges and fixed builds in the vendor guidance — and an attacker only needs network access to the service (no user interaction or credentials). Successful exploitation could lead to full system compromise on vulnerable builds. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349

Is CVE-2026-72950 being exploited?

There are no public reports of active exploitation of CVE-2026-72950 as of 2026-09-29.

How to fix CVE-2026-72950

  1. Apply Microsoft updates that ship the fixes: for example, update to 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954 or 6.2.9200.26349 as appropriate for your branch.
  2. If you cannot patch immediately, block or restrict network access to the Routing and Remote Access Service (RRAS) from untrusted networks and limit exposure to management networks.
  3. Monitor network and host logs for unusual RRAS activity and signs of code execution or privilege elevation on systems that cannot yet be updated.
  4. Follow Microsoft guidance and test updates in staging before broad deployment to avoid service disruption.

Frequently asked questions

Is CVE-2026-72950 being actively exploited?

There are no public reports of exploitation of CVE-2026-72950 as of 2026-09-29.

Which Windows versions are affected by CVE-2026-72950?

Windows systems running the Routing and Remote Access Service are affected across multiple branches including Windows 10 (various builds), Windows 11 branches, and Windows Server 2012 within the build ranges listed by Microsoft; consult the vendor's affected-build list for exact versions.

Is there a patch for CVE-2026-72950?

Yes. Microsoft published updates that fix the issue; fixed builds include examples such as 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954 and 6.2.9200.26349 depending on the branch.

Does CVE-2026-72950 require authentication?

No. The vulnerability can be exploited without authentication; an attacker only needs network access to the affected Routing and Remote Access Service.

References