Windows NTFS Remote Code Execution Vulnerability
Plan PatchCVSS 8.8CVE-2026-69461Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary
Stack-based buffer overflow in Windows NTFS allows an attacker to execute code over a network. The vulnerability affects Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems. Exploitation requires user interaction with malicious network content. Microsoft has released patches for all affected versions.
What this means
What could happen
An attacker could send a specially crafted network request that exploits a buffer overflow in NTFS to run malicious code on a Windows computer or server with the same privileges as the system. This could allow unauthorized access to sensitive data, modification of files, or disruption of services running on that machine.
Who's at risk
This affects Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems used as OT workstations, engineering stations, historian servers, or SCADA client machines. Any Windows-based computer or server in your plant network that processes NTFS data could be vulnerable if not patched.
How it could be exploited
An attacker sends a malicious network packet targeting the NTFS stack buffer overflow. The attack requires user interaction (the victim must open or access the malicious content), but once triggered, the attacker gains code execution on the target system. This could affect OT workstations, engineering stations, or servers involved in process control or data management.
Prerequisites
- Network access to the target Windows system
- User interaction required (victim must open/access malicious content over network)
- Target system running affected Windows version
remotely exploitablehigh CVSS score (8.8)user interaction requiredaffects multiple Windows versions
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict network access to Windows systems from untrusted networks using firewall rules
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the 2026-Sep Windows security update to all affected systems
Long-term hardening
0/1HARDENINGSegment OT workstations and engineering stations from general IT networks to restrict malicious network traffic
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/f1a23c8d-564a-4360-b310-8d4cf05841c5Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.