Windows NTFS Remote Code Execution Vulnerability
Plan PatchCVSS 9.8CVE-2026-69463Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Heap-based buffer overflow in Windows NTFS allows remote code execution without authentication. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 on 32-bit, x64, and ARM64 architectures, including Server Core installations. Microsoft has released patched builds for all affected products in the September 2026 security update.
What this means
What could happen
A heap-based buffer overflow in NTFS could allow an attacker to run arbitrary code on Windows systems and servers. This affects workstations, domain controllers, and any Windows-based HMI or engineering station in your network.
Who's at risk
Windows IT staff should prioritize patching domain controllers, HMI workstations, engineering stations running Windows 10/11, and any Windows Server systems (2016, 2019, 2022, 2025) that handle OT data or provide remote access to control systems. This affects all current versions of Windows 10, Windows 11, Windows Server 2016–2025, and both standard and Server Core installations.
How it could be exploited
An attacker sends a specially crafted network request that triggers the buffer overflow in the NTFS driver, resulting in remote code execution with the privileges of the system process. No authentication or user interaction is required.
Prerequisites
- Network access to the target Windows system
- NTFS filesystem in use (default on Windows)
- No authentication required
remotely exploitableno authentication requiredlow complexityaffects critical Windows versions including domain controllers and HMI platforms
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/3Patching may require device reboot — plan for process interruption
HOTFIXApply the September 2026 Windows security update to all affected systems
HOTFIXPrioritize patching Windows Server systems (2016, 2019, 2022, 2025) and Windows 10/11 workstations used for HMI, engineering access, or data collection
HOTFIXTest patches in a non-production environment before deployment to avoid operational disruption
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/59c7996b-0246-4069-8493-03763e17f538Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.