CVE-2026-73023
Windows Imaging Component Remote Code Execution Vulnerability
Description
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
In plain language
AI Act nowCVE-2026-73023 is a Windows security flaw that can let someone on the network take over a device by crashing or running malicious code through the Windows Imaging Component; if you run the affected Windows versions, you should act quickly and install the fixed updates.
CVE-2026-73023 is a remote code execution weakness (CWE-122: heap-based buffer overflow) in the Windows Imaging Component, where a network attacker can send crafted data that triggers memory corruption without needing prior authentication; no CISA KEV listing and no public exploit code were found, but patch availability exists for multiple Windows releases.
What to do now
- Check whether the affected device runs one of these: Windows 10, Windows 11, Windows Server 2012/2012 R2, Windows Server 2016/2019/2022/2025.
- Verify the installed update level matches at least one of the “fixed in” versions for your specific Windows release.
- Install the security update for CVE-2026-73023 from Microsoft and reboot if your organization requires it for update completion.
- After updating, confirm the system reports the expected patched build/update level and that Windows Update shows the machine as up to date.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows zero-day
- Microsoft and Adobe Patch Tuesday, September 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Microsoft Exchange Server Qualys
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysen-us·BleepingComputer· Exploited Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-73023 and every CVE in our database. Create a free account — no credit card required.
Create Free Account