CVE-2026-69525
Windows Remote Desktop Services use-after-free allows unauthenticated remote code execution (CVE-2026-69525)
Windows Remote Desktop Services use-after-free (CVE-2026-69525) allows unauthorised remote code execution over the network. CVSS 9.8 Critical; Microsoft rates it Important. No exploitation or public disclosure is recorded. Apply the September 2026 security update.
What happened
The vulnerability is a use-after-free (CWE-416) in Windows Remote Desktop Services. An attacker who can reach the service over a network can trigger the flaw to execute code on the affected host. The CVSS v3.1 score is 9.8 Critical: the attack is network-based, has low complexity, requires no privileges and no user interaction, and can have high impact on confidentiality, integrity and availability. Microsoft rates the issue Important.
Microsoft has not published a workaround. No exploitation has been reported, the vulnerability has not been publicly disclosed, and it is not listed in the CISA Known Exploited Vulnerabilities catalogue.
Who is affected
The CVE record names these affected releases: Windows 10 Version 1607 before 10.0.14393.9512; Windows 10 Version 1809 before 10.0.17763.9245; Windows 10 Version 21H2 before 10.0.19044.7725; Windows 10 Version 22H2 before 10.0.19045.7725; Windows 11 version 23H2 before 10.0.22631.7582; Windows 11 Version 24H2 before 10.0.26100.9445; Windows 11 Version 25H2 before 10.0.26200.9445; Windows 11 version 26H1 before 10.0.28000.2954; Windows Server 2012 and Windows Server 2012 (Server Core installation) before 6.2.9200.26349; and Windows Server 2012 R2 before 6.3.9600.23398. The fixed-version list on this page also includes builds for Windows Server 2016, Windows Server 2019, Windows Server 2022 and Windows Server 2025.
What to do now
- Apply the Microsoft security update from the 2026-Sep bundle. Fixed builds include: Windows 10 1607 10.0.14393.9512 (KB5123099); Windows 10 1809 10.0.17763.9245 (KB5122876); Windows 10 21H2/22H2 10.0.19044.7725 / 10.0.19045.7725 (KB5122878); Windows 11 23H2 10.0.22631.7582 (KB5122880); Windows 11 24H2/25H2 10.0.26100.9445 / 10.0.26200.9445 (KB5124008); Windows 11 26H1 10.0.28000.2954 (KB5124012); Windows Server 2012 and Core 6.2.9200.26349 (KB5123065); Windows Server 2012 R2 and Core 6.3.9600.23398 (KB5123066); Windows Server 2016 and Core 10.0.14393.9512 (KB5123099); Windows Server 2019 and Core 10.0.17763.9245 (KB5122876); Windows Server 2022 10.0.20348.5622 (KB5122882); Windows Server 2025 and Core 10.0.26100.33438 (KB5122871).
- Prioritise hosts where Remote Desktop Services is reachable from untrusted networks.
- Where the service does not need to be internet-facing, restrict access with firewalls, VPN or network segmentation.
- Microsoft has not published a workaround, so if you cannot patch immediately, isolate unpatched hosts from network exposure and monitor sign-in activity.
How to detect it
Microsoft's advisory does not state specific indicators of compromise for this CVE. As a practical check, identify any Remote Desktop Services host reachable from the internet or guest networks and review sign-in events for unexpected accounts, repeated failed attempts, or successful connections from unfamiliar sources. Treat unpatched hosts with network exposure as urgent.
Beyond the patch
This is a reminder that unauthenticated network-facing services should be found before an advisory names them. Virtual CISO Services (vCISO) helps map exposed Remote Desktop Services and other open management ports, and Managed Detection & Response (MDR) provides EDR and SIEM visibility to spot code execution or credential abuse after a service is reached. Patch first, then confirm your exposure picture.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Windows 10 Version 1607 | 10.0.14393.0 – < 10.0.14393.9512 | 10.0.14393.9512 |
| Windows 10 Version 1809 | 10.0.17763.0 – < 10.0.17763.9245 | 10.0.17763.9245 |
| Windows 10 Version 21H2 | 10.0.19044.0 – < 10.0.19044.7725 | 10.0.19044.7725 |
| Windows 10 Version 22H2 | 10.0.19045.0 – < 10.0.19045.7725 | 10.0.19045.7725 |
| Windows 11 version 23H2 | 10.0.22631.0 – < 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 23H2 | 10.0.22631.0 – < 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 24H2 | 10.0.26100.0 – < 10.0.26100.9445 | 10.0.26100.9445 |
| Windows 11 Version 25H2 | 10.0.26200.0 – < 10.0.26200.9445 | 10.0.26200.9445 |
| Windows 11 version 26H1 | 10.0.28000.0 – < 10.0.28000.2954 | 10.0.28000.2954 |
| Windows Server 2012 | 6.2.9200.0 – < 6.2.9200.26349 | 6.2.9200.26349 (Server Core installation) 6.2.9200.26349 R2 6.3.9600.23398 R2 (Server Core installation) 6.3.9600.23398 |
| Windows Server 2012 (Server Core installation) | 6.2.9200.0 – < 6.2.9200.26349 | 6.2.9200.26349 |
| Windows Server 2012 R2 | 6.3.9600.0 – < 6.3.9600.23398 | 6.3.9600.23398 (Server Core installation) 6.3.9600.23398 |