Microsoft has disclosed a critical remote code execution flaw in the Windows Routing and Remote Access Service (RRAS) carrying a CVSS 3.1 score of 9.8, affecting nearly every supported Windows client and server release.
What Is It
CVE-2026-69590 is a remote code execution vulnerability in the Windows Routing and Remote Access Service (RRAS). Per Microsoft's description, the flaw "allows attacker to gain an unauthorized access to victim's machine." It was published on 2026-09-08 and is currently in "Awaiting Analysis" status at NVD.
Why It Matters
The CVSS 3.1 vector, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, describes the worst-case profile for a network service bug: exploitable over the network, low attack complexity, no privileges required, and no user interaction. A successful attack yields high impact to confidentiality, integrity, and availability. RRAS is a role commonly exposed at network boundaries for VPN and routing duties, which places vulnerable hosts in exactly the position an unauthenticated remote attacker wants them.
CVE-2026-69590 does not appear in CISA's Known Exploited Vulnerabilities catalog as of 2026-09-08 (see Sources), so active exploitation is not confirmed at this time.
What's Vulnerable
Microsoft lists affected builds across the current Windows estate. Client platforms include Windows 10 versions 1607, 1809, 21H2, and 22H2, plus Windows 11 versions 23H2, 24H2, 25H2, and 26H1 on x64 and ARM64. Server platforms include Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations.
Selected fixed builds:
- Windows 10 1607 / Server 2016, 10.0.14393.9512
- Windows 10 1809 / Server 2019, 10.0.17763.9245
- Windows 10 21H2 / 22H2, 10.0.19044.7725 / 10.0.19045.7725
- Windows 11 23H2, 10.0.22631.7582
- Windows 11 24H2 / 25H2, 10.0.26100.9445 / 10.0.26200.9445
- Windows 11 26H1, 10.0.28000.2954
- Windows Server 2012, 6.2.9200.26349; Server 2012 R2, 6.3.9600.23397
- Windows Server 2022, 10.0.20348.5622
Windows Server 2025 and Windows 11 24H2 are built from the same 10.0.26100 servicing branch, so a single fixed revision governs both. Confirm the exact 26100 revision for each product directly in the MSRC Update Guide before using it to validate patch state.
Patch Status
Microsoft has shipped fixed builds for all listed products, as reflected in the version ranges above. Administrators should update affected systems to at or above the corresponding fixed build. No KEV remediation deadline applies, as the CVE is not currently listed in CISA's Known Exploited Vulnerabilities catalog.
Sources
- Microsoft Security Response Center; MSRC Update Guide: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69590
- NVD, CVE-2026-69590: https://nvd.nist.gov/vuln/detail/CVE-2026-69590
- CISA, Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog