Microsoft disclosed an out-of-bounds write in the Windows RPC Runtime that lets an unauthorized attacker execute code over a network, rated CVSS 9.8 (Critical).
What Is It
CVE-2026-69819 is an out-of-bounds write in RPC Runtime that allows an unauthorized attacker to execute code over a network. Microsoft ([email protected]) is the assigning source, and the CVE was published on 2026-09-08. NVD lists the record as "Awaiting Analysis," so deeper NVD-side enrichment is still pending.
Microsoft scored the issue CVSS 3.1 at 9.8 CRITICAL with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Why It Matters
The vector is network-attackable at low attack complexity, requires no privileges and no user interaction, and carries high impact to confidentiality, integrity, and availability. RPC Runtime is a core Windows component present across the entire supported client and server line, which makes the exposed surface unusually wide for an unauthenticated RCE.
There is no CISA KEV entry for CVE-2026-69819 in the supplied source material, so active exploitation is not confirmed at this time.
What's Vulnerable
Microsoft lists affected builds across Windows client and server:
- Windows 10: 1607 (< 10.0.14393.9512), 1809 (< 10.0.17763.9245), 21H2 and 22H2 (< 10.0.19044.7725 / 10.0.19045.7725)
- Windows 11: 23H2 (< 10.0.22631.7582), 24H2 (< 10.0.26100.9445), 25H2 (< 10.0.26200.9445), 26H1 (< 10.0.28000.2954)
- Windows Server 2012 / 2012 R2: < 6.2.9200.26349 / < 6.3.9600.23397, including Server Core installations
- Windows Server 2016 / 2019: < 10.0.14393.9512 / < 10.0.17763.9245, including Server Core installations
- Windows Server 2022: < 10.0.20348.5622
- Windows Server 2025: < 10.0.26100.9445, including Server Core installations; Server 2025 shares the 10.0.26100 build branch with Windows 11 24H2
Affected platforms span 32-bit, x64-based, and ARM64-based systems depending on the product.
Patch Status
The "less than" build numbers above are the fixed thresholds; systems at or above the listed build for their product are patched. No KEV remediation deadline or required action was supplied for this CVE. Consult the Microsoft Security Response Center update guide entry for the specific update package per product.
Sources
- Microsoft Security Response Center; Update Guide, CVE-2026-69819: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69819
- NVD, CVE-2026-69819: https://nvd.nist.gov/vuln/detail/CVE-2026-69819
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog