DIRAS TAKE
Urgent: patch exposed SSTP endpoints immediately because this vulnerability permits unauthenticated remote code execution over the network. Apply vendor updates or block SSTP exposure until systems are updated.
What is CVE-2026-73009?
An unauthenticated attacker can remotely execute arbitrary code against Windows systems that accept SSTP connections. CVE-2026-73009 is a use-after-free flaw in the Secure Socket Tunneling Protocol implementation that allows code execution over the network without user interaction. Affected builds include multiple Windows 10, Windows 11 branches and Windows Server 2012 releases (see fixed build numbers below); an attacker needs network access to an SSTP service on the target and no valid credentials. The weakness is classified as CWE-416 (Use After Free).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 10 Version 1607 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1607 10.x | 10.0.14393.0 – before 10.0.14393.9512 | 10.0.14393.9512 |
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9245 | 10.0.17763.9245 |
| Windows 10 Version 21H2 10.x | 10.0.19044.0 – before 10.0.19044.7725 | 10.0.19044.7725 |
| Windows 10 Version 22H2 10.x | 10.0.19045.0 – before 10.0.19045.7725 | 10.0.19045.7725 |
| Windows 11 version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 24H2 10.x | 10.0.26100.0 – before 10.0.26100.9445 | 10.0.26100.9445 |
| Windows 11 Version 25H2 10.x | 10.0.26200.0 – before 10.0.26200.9445 | 10.0.26200.9445 |
| Windows 11 version 26H1 10.x | 10.0.28000.0 – before 10.0.28000.2954 | 10.0.28000.2954 |
| Windows Server 2012 6.x | 6.2.9200.0 – before 6.2.9200.26349 | 6.2.9200.26349 |
Is CVE-2026-73009 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-73009
- Apply Microsoft's updates that fix this issue: upgrade to builds 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954, or 6.2.9200.26349 as appropriate for your branch.
- If you cannot patch immediately, restrict network exposure of SSTP services using firewalls and VPN gateway access controls.
- Monitor network and host logs for unexpected SSTP connections and signs of exploitation, and apply vendor guidance from Microsoft.
Frequently asked questions
Is CVE-2026-73009 being actively exploited?
There are no public reports of exploitation of CVE-2026-73009 as of 2026-09-29.
Which Windows versions are affected by CVE-2026-73009?
Multiple Windows 10 and Windows 11 branches plus Windows Server 2012 builds are affected; affected build ranges and their fixed build numbers are listed in the vendor advisory and in the fixed versions above.
Is there a patch for CVE-2026-73009?
Yes. Microsoft published fixes; upgrade to the fixed builds shown above for your Windows branch to remediate this issue.
Does CVE-2026-73009 require authentication?
No. The flaw allows an unauthenticated attacker with network access to a system's SSTP service to execute code.
References
- nvd.nist.gov/vuln/detail/CVE-2026-73009
- cve.org/CVERecord?id=CVE-2026-73009
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73009
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026