• PATCH AVAILABLE

CVE-2026-73010: pre-auth remote code execution in Microsoft Windows 10 Version 1809

An unauthenticated attacker can execute code remotely against Windows components due to a use-after-free vulnerability tracked as CVE-2026-73010. Affected builds include Windows 10 Version 1809 (10.0.17763.0 through before 10.0.17763.9245) and multiple Windows Server branches listed by Microsoft; fixed builds are provided. The flaw can be triggered over a network without user interaction or credentials, allowing code execution with system impact on vulnerable hosts reachable by an attacker.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-416
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent — this is a pre-auth remote code execution vulnerability and Microsoft published fixes; prioritize installing the listed fixed builds for affected Windows 10 and Server branches or otherwise block network exposure to vulnerable hosts.

What is CVE-2026-73010?

An unauthenticated attacker can execute code remotely against Windows components due to a use-after-free vulnerability tracked as CVE-2026-73010. Affected builds include Windows 10 Version 1809 (10.0.17763.0 through before 10.0.17763.9245) and multiple Windows Server branches listed by Microsoft; fixed builds are provided. The flaw can be triggered over a network without user interaction or credentials, allowing code execution with system impact on vulnerable hosts reachable by an attacker. The weakness is classified as CWE-416 (Use After Free).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1809 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows Server 2019 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows Server 2019 (Server Core installation) 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows Server 2022 10.x10.0.20348.0 – before 10.0.20348.562210.0.20348.5622
Windows Server 2025 10.x10.0.26100.0 – before 10.0.26100.3343810.0.26100.33438
Windows Server 2025 (Server Core installation) 10.x10.0.26100.0 – before 10.0.26100.3343810.0.26100.33438

Is CVE-2026-73010 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-73010

  1. Install the Microsoft fixes: update Windows 10 Version 1809 to build 10.0.17763.9245 and affected Server branches to their listed fixed builds.
  2. If you cannot patch immediately, restrict network exposure of vulnerable systems and block unnecessary inbound access.
  3. Monitor affected hosts for suspicious activity and review network logs for unexpected remote connections to vulnerable systems.
  4. Follow Microsoft's guidance and apply vendor-recommended mitigations if available.

Frequently asked questions

Is CVE-2026-73010 being actively exploited?

There are no public reports of exploitation of CVE-2026-73010 as of 2026-09-29.

Which Windows 10 Version 1809 and Server versions are affected by CVE-2026-73010?

Microsoft lists affected builds including Windows 10 Version 1809 10.0.17763.0 through before 10.0.17763.9245 and several Windows Server branches with similar pre-fixed build ranges; consult the vendor advisory for the full affected build ranges.

Is there a patch for CVE-2026-73010?

Yes. Microsoft published fixes; affected Windows 10 Version 1809 is fixed in build 10.0.17763.9245 and corresponding fixed builds are provided for the listed Server branches.

Does CVE-2026-73010 require authentication?

No. The vulnerability can be exploited without authentication over the network against vulnerable Windows 10 and Server builds.

References