Remote Desktop Services Remote Code Execution Vulnerability
Plan PatchCVSS 9.8CVE-2026-69525Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Use-after-free vulnerability in Windows Remote Desktop Services allows an unauthenticated attacker to execute arbitrary code over the network without user interaction.
What this means
What could happen
An attacker can remotely execute arbitrary code on systems running Remote Desktop Services, potentially gaining full control of the machine. This could allow manipulation of SCADA systems, HMI servers, or engineering workstations that rely on RDP for remote access and administration.
Who's at risk
Windows Server 2016, 2019, 2022, and 2025 systems; Windows 10 and Windows 11 across all recent versions. Impacts organizations using RDP-based remote access for engineering workstations, HMI servers, SCADA administrative systems, and remote plant management. Any facility relying on Windows servers or desktops for supervisory control should be considered at risk.
How it could be exploited
An attacker sends a specially crafted network request to the Remote Desktop Services port (typically TCP 3389) on an unpatched system. The use-after-free flaw allows the attacker to execute code with the privileges of the RDP service, gaining command execution without authentication.
Prerequisites
- Network access to TCP port 3389 (Remote Desktop Services)
- Target system running vulnerable Windows version with RDP enabled
- No authentication required
remotely exploitableno authentication requiredlow complexityhigh CVSS score (9.8)affects remote administration infrastructure
Exploitability
Some exploitation risk — EPSS score 1.0%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/5
Do now
0/4HOTFIXApply Microsoft's September 2026 security update to all affected Windows Server and Windows 10/11 systems immediately
WORKAROUNDRestrict network access to TCP port 3389 (Remote Desktop Services) at the firewall to only authorized engineering workstations and administrative networks
HARDENINGDisable Remote Desktop Services on systems that do not require remote access capability
WORKAROUNDEnable Network Level Authentication (NLA) on Remote Desktop Services to require user credentials before any RDP communication is processed
Long-term hardening
0/1HARDENINGImplement network segmentation to isolate SCADA and HMI systems from general corporate networks, restricting RDP access to a secured administrative network
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/360996b1-e2b0-4d77-9a8d-b6eb4fa2977bGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.