DIRAS TAKE
Urgent: this is a network unauthenticated remote code execution — an attacker only needs network access (no login), so prioritize deploying the provided fixes or otherwise isolating ICS-exposed hosts.
What is CVE-2026-72983?
An unauthenticated attacker can execute arbitrary code over the network against Windows systems that expose Internet Connection Sharing (ICS). CVE-2026-72983 is a use-after-free flaw in ICS that allows remote code execution. Affected builds include multiple Windows 10 branches (for example Windows 10 Version 1607: 10.0.14393.0 through before 10.0.14393.9512) as well as several Windows 11 and Windows Server 2012 builds; an attacker needs only network access — no credentials or user interaction — to exploit the bug. The weakness is classified as CWE-416 (Use After Free).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 10 Version 1607 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1607 10.x | 10.0.14393.0 – before 10.0.14393.9512 | 10.0.14393.9512 |
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9245 | 10.0.17763.9245 |
| Windows 10 Version 21H2 10.x | 10.0.19044.0 – before 10.0.19044.7725 | 10.0.19044.7725 |
| Windows 10 Version 22H2 10.x | 10.0.19045.0 – before 10.0.19045.7725 | 10.0.19045.7725 |
| Windows 11 version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 24H2 10.x | 10.0.26100.0 – before 10.0.26100.9445 | 10.0.26100.9445 |
| Windows 11 Version 25H2 10.x | 10.0.26200.0 – before 10.0.26200.9445 | 10.0.26200.9445 |
| Windows 11 version 26H1 10.x | 10.0.28000.0 – before 10.0.28000.2954 | 10.0.28000.2954 |
| Windows Server 2012 6.x | 6.2.9200.0 – before 6.2.9200.26349 | 6.2.9200.26349 |
Is CVE-2026-72983 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-72983
- Apply Microsoft updates that contain the fixes for the affected branches (for example 10.0.14393.9512 and later for Windows 10 Version 1607).
- Identify hosts running Internet Connection Sharing and update them to the fixed builds listed by the vendor.
- Restrict network exposure of ICS services using firewall rules and network segmentation for internet-facing or untrusted networks.
- Monitor affected hosts for suspicious activity and review network logs for unexpected connections to ICS services.
Frequently asked questions
Is CVE-2026-72983 being actively exploited?
There are no public reports of active exploitation of CVE-2026-72983 as of 2026-09-29.
Which Windows 10 Version 1607 versions are affected by CVE-2026-72983?
Windows 10 Version 1607 builds from 10.0.14393.0 up to but not including 10.0.14393.9512 are affected; 10.0.14393.9512 is the fixed build.
Is there a patch for CVE-2026-72983?
Yes. Microsoft published fixed builds for the listed branches (for example 10.0.14393.9512 for Windows 10 Version 1607 and corresponding fixed builds for other affected releases).
Does CVE-2026-72983 require authentication?
No. The vulnerability in Windows Internet Connection Sharing can be exploited over the network without authentication or user interaction.
References
- nvd.nist.gov/vuln/detail/CVE-2026-72983
- cve.org/CVERecord?id=CVE-2026-72983
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72983
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026