DIRAS TAKE
Patch urgently: the flaw allows remote code execution without authentication, so prioritize updates for exposed hosts and apply Microsoft's fixed builds immediately.
What is CVE-2026-77493?
An unauthenticated attacker can run arbitrary code on affected Windows systems by exploiting a double-free flaw in the Microsoft Graphics Component. CVE-2026-77493 impacts multiple Windows 10, Windows 11, and Windows Server branches; affected build ranges include Windows 10 Version 1607 (10.0.14393.0 through before 10.0.14393.9512), Windows 10/11 branches listed in the vendor advisory, and Windows Server 2012 (6.2.9200.0 through before 6.2.9200.26349). Successful exploitation requires network access and no user interaction or credentials.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 10 Version 1607 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1607 10.x | 10.0.14393.0 – before 10.0.14393.9512 | 10.0.14393.9512 |
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9245 | 10.0.17763.9245 |
| Windows 10 Version 21H2 10.x | 10.0.19044.0 – before 10.0.19044.7725 | 10.0.19044.7725 |
| Windows 10 Version 22H2 10.x | 10.0.19045.0 – before 10.0.19045.7725 | 10.0.19045.7725 |
| Windows 11 version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 24H2 10.x | 10.0.26100.0 – before 10.0.26100.9445 | 10.0.26100.9445 |
| Windows 11 Version 25H2 10.x | 10.0.26200.0 – before 10.0.26200.9445 | 10.0.26200.9445 |
| Windows 11 version 26H1 10.x | 10.0.28000.0 – before 10.0.28000.2954 | 10.0.28000.2954 |
| Windows Server 2012 6.x | 6.2.9200.0 – before 6.2.9200.26349 | 6.2.9200.26349 |
Is CVE-2026-77493 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-77493
- Install Microsoft's security updates that bring devices to the fixed builds (for example 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954, or 6.2.9200.26349 as applicable).
- Prioritize patching internet-facing and high-value systems first, then roll out to all remaining affected hosts.
- If immediate patching is not possible, restrict network exposure of vulnerable hosts and apply firewall rules to limit incoming access to trusted sources.
- Monitor endpoint and network logs for suspicious activity and signs of exploitation targeting the Graphics Component.
Frequently asked questions
Is CVE-2026-77493 being actively exploited?
There are no public reports of exploitation of CVE-2026-77493 as of 2026-09-29.
Which Windows versions are affected by CVE-2026-77493?
Multiple Windows 10 and Windows 11 branches plus Windows Server 2012 are affected; affected build ranges and fixed builds are listed in the vendor advisory and include the build numbers shown in the advisory.
Is there a patch for CVE-2026-77493?
Yes. Microsoft published fixes that update affected systems to specific fixed builds such as 10.0.14393.9512 and other builds listed in the advisory.
Does CVE-2026-77493 require authentication?
No. The vulnerability can be exploited without authentication or user interaction against affected Windows systems.
References
- nvd.nist.gov/vuln/detail/CVE-2026-77493
- cve.org/CVERecord?id=CVE-2026-77493
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77493
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026