Windows TCP/IP Remote Code Execution Vulnerability
A stack-based buffer overflow exists in the Windows TCP/IP stack that allows an unauthenticated attacker to execute arbitrary code over the network. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 on both 32-bit and 64-bit architectures. Exploitation requires sending a specially crafted network packet but does not require user interaction or elevated privileges. Microsoft has released patches for all affected versions as part of the August 2026 security update.
- Network connectivity to the affected Windows system
- Target must be running a vulnerable version of Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025
- No authentication required
Patching may require device reboot — plan for process interruption
/api/v1/advisories/3904368d-1a09-4137-bc0e-b249ab41213fGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.