CVE-2026-69525
Remote Desktop Services Remote Code Execution Vulnerability
Description
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
In plain language
AI Act nowThis Windows Remote Desktop Services bug can let an attacker run code over the network, even without you clicking anything—so most small businesses using remote desktop should treat it as urgent and patch now.
CVE-2026-69525 is a remote-code-execution issue in Windows Remote Desktop Services caused by a use-after-free weakness, allowing unauthenticated network attackers to trigger the fault and execute code.
What to do now
- Check whether you run Windows Remote Desktop Services (RDP) and identify your exact Windows version and build number (e.g., “Windows 10” or “Windows Server 2019” plus the build).
- Compare your build to the fixed versions below; if you are on an affected build, plan an immediate update to a fixed build.
- Apply the available Windows updates that move you to at least the fixed build for your exact product/branch:
- Windows 10: update to 10.0.14393.9512, or 10.0.17763.9245, or 10.0.19044.7725, or 10.0.19045.7725
- Windows 11: update to 10.0.22631.7582, or 10.0.26100.9445, or 10.0.26200.9445, or 10.0.28000.2954
- Windows Server 2012: update to 6.2.9200.26349
- Windows Server 2012 R2: update to 6.3.9600.23397
- Windows Server 2016: update to 10.0.14393.9512
- After updating, confirm the build number changed and that Remote Desktop Services continues to run as expected; then re-test any remote-access workflows you rely on.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft выпустила патчи для почти 1000 уязвимостейru-ru·Хакер (xakep.ru)· Exploited Windows patch-tuesday
- Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Daysen·The Hacker News· Exploited Windows zero-day
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows zero-day
- Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Daysen-us·SecurityWeek· Exploited Windows ALPC Tenable
- Microsoft and Adobe Patch Tuesday, September 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Microsoft Exchange Server Qualys
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysen-us·BleepingComputer· Exploited Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-69525 and every CVE in our database. Create a free account — no credit card required.
Create Free Account