• PATCH AVAILABLE

CVE-2026-77493: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An unauthenticated attacker can run arbitrary code on affected Windows systems by exploiting a double-free flaw in the Microsoft Graphics Component. CVE-2026-77493 impacts multiple Windows 10, Windows 11, and Windows Server branches; affected build ranges include Windows 10 Version 1607 (10.0.14393.0 through before 10.0.14393.9512), Windows 10/11 branches listed in the vendor advisory, and Windows Server 2012 (6.2.9200.0 through before 6.2.9200.26349). Successful exploitation requires network access and no user interaction or credentials.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-415
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Patch urgently: the flaw allows remote code execution without authentication, so prioritize updates for exposed hosts and apply Microsoft's fixed builds immediately.

What is CVE-2026-77493?

An unauthenticated attacker can run arbitrary code on affected Windows systems by exploiting a double-free flaw in the Microsoft Graphics Component. CVE-2026-77493 impacts multiple Windows 10, Windows 11, and Windows Server branches; affected build ranges include Windows 10 Version 1607 (10.0.14393.0 through before 10.0.14393.9512), Windows 10/11 branches listed in the vendor advisory, and Windows Server 2012 (6.2.9200.0 through before 6.2.9200.26349). Successful exploitation requires network access and no user interaction or credentials.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349

Is CVE-2026-77493 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-77493

  1. Install Microsoft's security updates that bring devices to the fixed builds (for example 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954, or 6.2.9200.26349 as applicable).
  2. Prioritize patching internet-facing and high-value systems first, then roll out to all remaining affected hosts.
  3. If immediate patching is not possible, restrict network exposure of vulnerable hosts and apply firewall rules to limit incoming access to trusted sources.
  4. Monitor endpoint and network logs for suspicious activity and signs of exploitation targeting the Graphics Component.

Frequently asked questions

Is CVE-2026-77493 being actively exploited?

There are no public reports of exploitation of CVE-2026-77493 as of 2026-09-29.

Which Windows versions are affected by CVE-2026-77493?

Multiple Windows 10 and Windows 11 branches plus Windows Server 2012 are affected; affected build ranges and fixed builds are listed in the vendor advisory and include the build numbers shown in the advisory.

Is there a patch for CVE-2026-77493?

Yes. Microsoft published fixes that update affected systems to specific fixed builds such as 10.0.14393.9512 and other builds listed in the advisory.

Does CVE-2026-77493 require authentication?

No. The vulnerability can be exploited without authentication or user interaction against affected Windows systems.

References