• PATCH AVAILABLE

CVE-2026-72982: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An unauthenticated attacker can execute arbitrary code on Windows systems by exploiting a stack-based buffer overflow in the Netlogon service; this is tracked as CVE-2026-72982. The flaw affects multiple Windows 10, Windows 11 and Windows Server 2012 branches — specific vulnerable builds run from 10.0.14393.0 through before 10.0.14393.9512, 10.0.17763.0 through before 10.0.17763.9245, and additional builds listed as affected. Exploitation requires network access to the Netlogon service and does not require valid credentials or user interaction.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-121
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a critical remote code execution bug that requires no authentication and can be reached over the network, so prioritize installing the provided builds that contain the fixes.

What is CVE-2026-72982?

An unauthenticated attacker can execute arbitrary code on Windows systems by exploiting a stack-based buffer overflow in the Netlogon service; this is tracked as CVE-2026-72982. The flaw affects multiple Windows 10, Windows 11 and Windows Server 2012 branches — specific vulnerable builds run from 10.0.14393.0 through before 10.0.14393.9512, 10.0.17763.0 through before 10.0.17763.9245, and additional builds listed as affected. Exploitation requires network access to the Netlogon service and does not require valid credentials or user interaction.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349

Is CVE-2026-72982 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-72982

  1. Install the vendor updates that deliver the fixed builds (for example 10.0.14393.9512, 10.0.17763.9245 and the other fixed versions listed by Microsoft).
  2. If you cannot patch immediately, restrict network exposure to Netlogon endpoints and block access from untrusted networks.
  3. Monitor endpoints and network logs for unusual Netlogon activity and attempts to connect to domain controller RPC/Netlogon services.
  4. Follow Microsoft's guidance and deploy updates across all affected Windows 10, Windows 11 and Windows Server systems.

Frequently asked questions

Is CVE-2026-72982 being actively exploited?

There are no public reports of active exploitation of CVE-2026-72982 as of 2026-09-29.

Which Windows 10 Version 1607 versions are affected by CVE-2026-72982?

Windows 10 Version 1607 builds from 10.0.14393.0 up to but not including 10.0.14393.9512 are listed as affected; apply the fixed build 10.0.14393.9512.

Is there a patch for CVE-2026-72982?

Yes, Microsoft published fixes; affected branches include fixed builds such as 10.0.14393.9512, 10.0.17763.9245 and others noted in the vendor's affected list.

Does CVE-2026-72982 require authentication?

No, the Netlogon vulnerability does not require authentication and can be exploited over the network without valid credentials.

References