• PATCH AVAILABLE

CVE-2026-73025: authentication bypass in Microsoft Windows 10 Version 1607

An unauthorized attacker can bypass iSCSI authentication over a network to affect Windows hosts; this is tracked as CVE-2026-73025. The flaw impacts Windows 10 Version 1607 and 1809 branches and multiple Windows Server branches (Server 2012, 2012 R2, 2016, 2019) in the listed build ranges; vendors released fixed builds for each affected branch. An attacker needs network access to the iSCSI service and can act without valid credentials due to the weak authentication behavior.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00901
CWE
CWE-1390
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: treat this as a high-priority patching task because the flaw lets an unauthenticated remote attacker bypass iSCSI authentication; fixed builds are available for all affected branches. Apply the fixes or block iSCSI exposure immediately.

What is CVE-2026-73025?

An unauthorized attacker can bypass iSCSI authentication over a network to affect Windows hosts; this is tracked as CVE-2026-73025. The flaw impacts Windows 10 Version 1607 and 1809 branches and multiple Windows Server branches (Server 2012, 2012 R2, 2016, 2019) in the listed build ranges; vendors released fixed builds for each affected branch. An attacker needs network access to the iSCSI service and can act without valid credentials due to the weak authentication behavior.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349
Windows Server 2012 (Server Core installation) 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349
Windows Server 2012 R2 6.x6.3.9600.0 – before 6.3.9600.233986.3.9600.23398
Windows Server 2012 R2 (Server Core installation) 6.x6.3.9600.0 – before 6.3.9600.233986.3.9600.23398
Windows Server 2016 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows Server 2016 (Server Core installation) 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows Server 2019 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows Server 2019 (Server Core installation) 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245

Is CVE-2026-73025 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-73025

  1. Install the vendor fixed builds for affected branches (for example 10.0.14393.9512, 10.0.17763.9245, 6.2.9200.26349, 6.3.9600.23398).
  2. If you cannot patch immediately, restrict network access to iSCSI services to trusted networks and hosts only.
  3. Monitor iSCSI service logs and network traffic for unusual connection attempts and follow Microsoft guidance for remediation.
  4. Apply regular Windows updates and verify systems are running the fixed build numbers listed by Microsoft.

Frequently asked questions

Is CVE-2026-73025 being actively exploited?

There are no public reports of exploitation of CVE-2026-73025 as of 2026-09-29.

Which Windows 10 Version 1607 versions are affected by CVE-2026-73025?

Windows 10 Version 1607 builds from 10.0.14393.0 up to before 10.0.14393.9512 are affected; the issue is fixed in build 10.0.14393.9512.

Is there a patch for CVE-2026-73025?

Yes. Microsoft published fixes: affected branches have specific fixed builds such as 10.0.14393.9512, 10.0.17763.9245, 6.2.9200.26349, and 6.3.9600.23398—apply the corresponding update for your product.

Does CVE-2026-73025 require authentication?

No. The vulnerability allows an unauthorized network attacker to bypass iSCSI authentication on affected Windows systems.

References