Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-73009 2026-09-08

CVE-2026-73009: Critical Use-After-Free in Windows SSTP Enables Unauthenticated Remote Code Execution

"Microsoft disclosed a CVSS 9.8 use-after-free flaw in the Windows Secure Socket Tunneling Protocol (SSTP) that lets an unauthorized attacker execute code over a network against a broad range of Windows client and server…"

Microsoft disclosed a CVSS 9.8 use-after-free flaw in the Windows Secure Socket Tunneling Protocol (SSTP) that lets an unauthorized attacker execute code over a network against a broad range of Windows client and server builds.

What Is It

CVE-2026-73009 is a use-after-free vulnerability in Windows Secure Socket Tunneling Protocol (SSTP). Per Microsoft's description, it "allows an unauthorized attacker to execute code over a network." The CVE was published on 2026-09-08 and is currently in "Awaiting Analysis" status at NVD, with Microsoft ([email protected]) as the source identifier.

Why It Matters

Microsoft rates this CRITICAL with a CVSS 3.1 base score of 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The vector requires no privileges and no user interaction, is reachable over the network, and is rated low attack complexity, with high impact to confidentiality, integrity, and availability. SSTP is a VPN tunneling protocol, so affected servers are frequently exposed at the network edge by design.

Neither the NVD record nor the MSRC entry references a CISA KEV listing for this CVE, so there is no confirmed active exploitation and no federal remediation deadline associated with it at this time.

What's Vulnerable

Microsoft lists nearly the entire supported Windows fleet as affected below the fixed builds:

Windows Server 2025 and Windows 11 24H2 share the 26100 base build, so the Server 2025 fix ships in the same build lineage as the 10.0.26100.9445 revision listed for 24H2. Because this brief could not confirm the specific Server 2025 revision, administrators should read the target revision for that SKU directly from the MSRC Update Guide rather than assuming it matches the client build.

Affected platforms span 32-bit, x64-based, and ARM64-based systems.

Patch Status

Microsoft has shipped fixed builds for every affected product listed above; remediation is to update to at or above the corresponding build number. The MSRC Update Guide entry is the authoritative source for applicable updates. Neither the NVD record nor the MSRC entry specifies workarounds or mitigations.

Sources


One flag outside the article: the editorial note arrived truncated mid-sentence, and the Server 2025 fixed revision is not present in intel/CVE-2026-73009.md or anywhere else in the repo, so I could not restore an actual build number without inventing one. I removed the unsupported claim that MSRC's listed revisions "cannot both be correct" and replaced the hedge with an explicit statement that the revision is missing from this brief's source data. Give me the number (or the full note) and I'll drop it in.