Windows TCP/IP Remote Code Execution Vulnerability
Plan PatchCVSS 8.8CVE-2026-54999Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
A race condition in the Windows TCP/IP stack allows an attacker on the local network segment to execute arbitrary code without authentication or user interaction. The vulnerability affects all supported versions of Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 across all processor architectures (32-bit, x64, ARM64). Microsoft has released patches for all affected versions and rates exploitation as less likely.
What this means
What could happen
An attacker on your local network (adjacent network segment) could execute arbitrary code on affected Windows systems by exploiting a race condition in the TCP/IP stack, potentially gaining control of servers or workstations used in your operations.
Who's at risk
This affects all supported versions of Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025. Organizations running these systems as engineering workstations, HMI servers, or data acquisition systems should prioritize patching. Water utilities and electric utilities using Windows-based SCADA supervisory systems or Windows servers for operational data logging are at risk.
How it could be exploited
An attacker with access to your local network (same subnet or network segment) could send specially crafted TCP/IP packets that exploit a race condition in Windows networking code. If successful, this allows the attacker to run commands with the privileges of the affected system, which could include PLCs, HMI systems, or engineering workstations that depend on Windows servers.
Prerequisites
- Attacker must have network access to the same local network segment (adjacent network) as the affected system
- No credentials required
- No user interaction required
remotely exploitablelow complexityno authentication requiredaffects multiple critical Windows versionslocal network access required (lower risk than internet-facing but dangerous in shared OT/IT networks)
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXApply Microsoft's July 2026 security update to all affected Windows systems (Windows 10 all versions, Windows 11 all versions, Windows Server 2016, 2019, 2022, 2025)
Long-term hardening
0/2HARDENINGRestrict network access to your administrative and engineering workstations to prevent untrusted systems from reaching them over the local network (use VLAN segmentation or switch port security)
HARDENINGMonitor for and block any unusual TCP/IP traffic patterns or connection attempts from unexpected sources on your local network segments
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/30830716-c75c-4561-a7ee-e035bea5a7f6Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.