DIRAS TAKE
Urgent — this is a pre-auth remote code execution vulnerability and Microsoft published fixes; prioritize installing the listed fixed builds for affected Windows 10 and Server branches or otherwise block network exposure to vulnerable hosts.
What is CVE-2026-73010?
An unauthenticated attacker can execute code remotely against Windows components due to a use-after-free vulnerability tracked as CVE-2026-73010. Affected builds include Windows 10 Version 1809 (10.0.17763.0 through before 10.0.17763.9245) and multiple Windows Server branches listed by Microsoft; fixed builds are provided. The flaw can be triggered over a network without user interaction or credentials, allowing code execution with system impact on vulnerable hosts reachable by an attacker. The weakness is classified as CWE-416 (Use After Free).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 10 Version 1809 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9245 | 10.0.17763.9245 |
| Windows Server 2019 10.x | 10.0.17763.0 – before 10.0.17763.9245 | 10.0.17763.9245 |
| Windows Server 2019 (Server Core installation) 10.x | 10.0.17763.0 – before 10.0.17763.9245 | 10.0.17763.9245 |
| Windows Server 2022 10.x | 10.0.20348.0 – before 10.0.20348.5622 | 10.0.20348.5622 |
| Windows Server 2025 10.x | 10.0.26100.0 – before 10.0.26100.33438 | 10.0.26100.33438 |
| Windows Server 2025 (Server Core installation) 10.x | 10.0.26100.0 – before 10.0.26100.33438 | 10.0.26100.33438 |
Is CVE-2026-73010 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-73010
- Install the Microsoft fixes: update Windows 10 Version 1809 to build 10.0.17763.9245 and affected Server branches to their listed fixed builds.
- If you cannot patch immediately, restrict network exposure of vulnerable systems and block unnecessary inbound access.
- Monitor affected hosts for suspicious activity and review network logs for unexpected remote connections to vulnerable systems.
- Follow Microsoft's guidance and apply vendor-recommended mitigations if available.
Frequently asked questions
Is CVE-2026-73010 being actively exploited?
There are no public reports of exploitation of CVE-2026-73010 as of 2026-09-29.
Which Windows 10 Version 1809 and Server versions are affected by CVE-2026-73010?
Microsoft lists affected builds including Windows 10 Version 1809 10.0.17763.0 through before 10.0.17763.9245 and several Windows Server branches with similar pre-fixed build ranges; consult the vendor advisory for the full affected build ranges.
Is there a patch for CVE-2026-73010?
Yes. Microsoft published fixes; affected Windows 10 Version 1809 is fixed in build 10.0.17763.9245 and corresponding fixed builds are provided for the listed Server branches.
Does CVE-2026-73010 require authentication?
No. The vulnerability can be exploited without authentication over the network against vulnerable Windows 10 and Server builds.
References
- nvd.nist.gov/vuln/detail/CVE-2026-73010
- cve.org/CVERecord?id=CVE-2026-73010
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73010
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026