Vulnerability Intelligence Report
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2026-69590
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:0.98%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-122 ↗CWE-122: Heap-based Buffer Overflow
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Microsoft | Windows 10 Version 1607 | 10.0.14393.0 < 10.0.14393.9512 (affected) |
| Microsoft | Windows 10 Version 1809 | 10.0.17763.0 < 10.0.17763.9245 (affected) |
| Microsoft | Windows 10 Version 21H2 | 10.0.19044.0 < 10.0.19044.7725 (affected) |
| Microsoft | Windows 10 Version 22H2 | 10.0.19045.0 < 10.0.19045.7725 (affected) |
| Microsoft | Windows 11 version 23H2 | 10.0.22631.0 < 10.0.22631.7582 (affected) |
| Microsoft | Windows 11 Version 23H2 | 10.0.22631.0 < 10.0.22631.7582 (affected) |
| Microsoft | Windows 11 Version 24H2 | 10.0.26100.0 < 10.0.26100.9445 (affected) |
| Microsoft | Windows 11 Version 25H2 | 10.0.26200.0 < 10.0.26200.9445 (affected) |
| Microsoft | Windows 11 version 26H1 | 10.0.28000.0 < 10.0.28000.2954 (affected) |
| Microsoft | Windows Server 2012 | 6.2.9200.0 < 6.2.9200.26349 (affected) |
| Microsoft | Windows Server 2012 (Server Core installation) | 6.2.9200.0 < 6.2.9200.26349 (affected) |
| Microsoft | Windows Server 2012 R2 | 6.3.9600.0 < 6.3.9600.23397 (affected) |
| Microsoft | Windows Server 2012 R2 (Server Core installation) | 6.3.9600.0 < 6.3.9600.23397 (affected) |
| Microsoft | Windows Server 2016 | 10.0.14393.0 < 10.0.14393.9512 (affected) |
| Microsoft | Windows Server 2016 (Server Core installation) | 10.0.14393.0 < 10.0.14393.9512 (affected) |
| Microsoft | Windows Server 2019 | 10.0.17763.0 < 10.0.17763.9245 (affected) |
| Microsoft | Windows Server 2019 (Server Core installation) | 10.0.17763.0 < 10.0.17763.9245 (affected) |
| Microsoft | Windows Server 2022 | 10.0.20348.0 < 10.0.20348.5622 (affected) |
| Microsoft | Windows Server 2025 | 10.0.26100.0 < 10.0.26100.33438 (affected) |
| Microsoft | Windows Server 2025 (Server Core installation) | 10.0.26100.0 < 10.0.26100.33438 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.976%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Microsoft Corporation · Vendor · USA |
| Reserved | 2026-08-03T21:18:49 |
| Published | 2026-09-08T17:17:29 |
| Patch Date | 2026-09-08 |
| Last Updated | 2026-09-18T20:45:01 |
Community Chatter & Buzz