Windows Remote Desktop Remote Code Execution Vulnerability
Plan PatchCVSS 8.8CVE-2026-69518Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary
A heap-based buffer overflow in Windows Remote Desktop Protocol (RDP) allows an attacker to execute arbitrary code remotely over the network without authentication. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 across 32-bit, x64, and ARM64 architectures.
What this means
What could happen
An attacker with network access to a Windows machine with Remote Desktop enabled could run arbitrary code with system privileges, potentially taking control of that computer and any systems it can reach on your network.
Who's at risk
This affects any organization running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 with Remote Desktop Protocol enabled. This includes IT departments using RDP for remote administration, terminal servers providing access to applications, engineering workstations in control networks, and any Windows-based SCADA or HMI systems that use RDP for remote access or management.
How it could be exploited
An attacker sends a specially crafted network packet to port 3389 (Remote Desktop Protocol) without needing valid credentials. The packet triggers a heap buffer overflow in the RDP service, allowing the attacker to execute code remotely before any user authentication occurs.
Prerequisites
- Network access to port 3389 (RDP service)
- Remote Desktop service enabled on target machine
- No authentication required
remotely exploitableno authentication requiredlow complexityaffects administrative access
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/2HARDENINGIf RDP is not required, disable Remote Desktop Protocol (RDP) in Settings > System > Remote Desktop
WORKAROUNDRestrict network access to port 3389 via firewall to only authorized workstations or VPN connections
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply Microsoft's September 2026 security update to all affected Windows systems
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/099c54e0-fb64-40bb-8ced-abdda03c1178Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.