CVE-2026-69676
Windows Kerberos Remote Code Execution Vulnerability
Description
Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker to execute code over a network.
In plain language
AI Act nowThis is a Windows security flaw that could let an attacker run code over the network by tricking the Windows login system (Kerberos); if you run supported Windows versions and your machines are reachable from other networks, you should act now and install the fixed updates.
CVE-2026-69676 is a Windows Kerberos Remote Code Execution issue involving an authentication bypass via capture-replay, which can let an attacker with low privileges run code over the network if they can reach the Kerberos service and meet the attacker access requirements.
What to do now
- Check every affected device for its exact Windows version/build (and whether it is on an older, unpatched branch from the list below).
- If you are on Windows 10, update each installation to at least one of these fixed builds: 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, or 10.0.19045.7725.
- If you are on Windows 11, update each installation to at least one of these fixed builds: 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, or 10.0.28000.2954.
- If you are on Windows Server, update each installation to at least one of these fixed builds: 6.2.9200.26349 (2012), 6.3.9600.23397 (2012 R2), 10.0.14393.9512 (2016), or 10.0.17763.9245 (2019).
- Install the update from Microsoft’s guidance page for CVE-2026-69676 (or trigger Microsoft Update/WSUS to pull it), then re-check the installed build number to confirm the fixed version is present.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successoren-us·Help Net Security· Exploited Windows Update Stack patch-tuesday
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows zero-day
- Microsoft and Adobe Patch Tuesday, September 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Microsoft Exchange Server Qualys
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysen-us·BleepingComputer· Exploited Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-69676 and every CVE in our database. Create a free account — no credit card required.
Create Free Account