Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-69590 2026-09-08

CVE-2026-69590: Critical Unauthenticated RCE in Windows RRAS

"Microsoft has disclosed a critical remote code execution flaw in the Windows Routing and Remote Access Service (RRAS) carrying a CVSS 3.1 score of 9.8, affecting nearly every supported Windows client and server release."

Microsoft has disclosed a critical remote code execution flaw in the Windows Routing and Remote Access Service (RRAS) carrying a CVSS 3.1 score of 9.8, affecting nearly every supported Windows client and server release.

What Is It

CVE-2026-69590 is a remote code execution vulnerability in the Windows Routing and Remote Access Service (RRAS). Per Microsoft's description, the flaw "allows attacker to gain an unauthorized access to victim's machine." It was published on 2026-09-08 and is currently in "Awaiting Analysis" status at NVD.

Why It Matters

The CVSS 3.1 vector, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, describes the worst-case profile for a network service bug: exploitable over the network, low attack complexity, no privileges required, and no user interaction. A successful attack yields high impact to confidentiality, integrity, and availability. RRAS is a role commonly exposed at network boundaries for VPN and routing duties, which places vulnerable hosts in exactly the position an unauthenticated remote attacker wants them.

CVE-2026-69590 does not appear in CISA's Known Exploited Vulnerabilities catalog as of 2026-09-08 (see Sources), so active exploitation is not confirmed at this time.

What's Vulnerable

Microsoft lists affected builds across the current Windows estate. Client platforms include Windows 10 versions 1607, 1809, 21H2, and 22H2, plus Windows 11 versions 23H2, 24H2, 25H2, and 26H1 on x64 and ARM64. Server platforms include Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations.

Selected fixed builds:

Windows Server 2025 and Windows 11 24H2 are built from the same 10.0.26100 servicing branch, so a single fixed revision governs both. Confirm the exact 26100 revision for each product directly in the MSRC Update Guide before using it to validate patch state.

Patch Status

Microsoft has shipped fixed builds for all listed products, as reflected in the version ranges above. Administrators should update affected systems to at or above the corresponding fixed build. No KEV remediation deadline applies, as the CVE is not currently listed in CISA's Known Exploited Vulnerabilities catalog.

Sources