CVE-2026-69769
Windows HTTP Print Provider Remote Code Execution Vulnerability
Description
Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network.
In plain language
AI Act nowCVE-2026-69769 is a serious Windows vulnerability that can let an attacker run code over the network on affected Windows versions; if you run Windows 10/11 or Windows Server, you should act soon and install the fixes.
CVE-2026-69769 is a heap-based buffer overflow in the Windows HTTP Print Provider that can enable remote code execution by a network-based attacker without authentication on affected Windows versions; Microsoft has released fixed builds.
What to do now
- Check which of these you run: Windows 10, Windows 11, or any listed Windows Server (2012/2012 R2/2016/2019/2022/2025).
- Confirm you’re on a vulnerable build by comparing your Windows version to the fixed versions Microsoft lists for CVE-2026-69769.
- Upgrade/patch now to the exact fixed version for your OS branch: Windows 10 (10.0.14393.9512 or 10.0.17763.9245 or 10.0.19044.7725 or 10.0.19045.7725), Windows 11 (10.0.22631.7582 or 10.0.26100.9445 or 10.0.26200.9445 or 10.0.28000.2954), Windows Server 2012 (6.2.9200.26349), Windows Server 2012 R2 (6.3.9600.23397), Windows Server 2016 (10.0.14393.9512), Windows Server 2019 (10.0.17763.9245).
- After patching, verify the OS build number changed to one of the fixed versions and that your update succeeded.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows zero-day
- Microsoft and Adobe Patch Tuesday, September 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Microsoft Exchange Server Qualys
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysen-us·BleepingComputer· Exploited Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-69769 and every CVE in our database. Create a free account — no credit card required.
Create Free Account