Remote Desktop Services Remote Code Execution Vulnerability
Plan PatchCVSS 7.1CVE-2026-69536Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityHigh
User InteractionRequired
Summary
A use-after-free vulnerability in Windows Remote Desktop Services allows an authorized attacker to execute code remotely over the network. The vulnerability affects multiple versions of Windows Server 2025 and Windows 11 (versions 23H2, 24H2, and 26H1) on both x64 and ARM64 architectures.
What this means
What could happen
An authenticated attacker with remote access to Remote Desktop Services could execute arbitrary code on the affected system, potentially compromising process control systems, data integrity, or availability of the server.
Who's at risk
System administrators and operators managing Windows Server 2025 and Windows 11 workstations (versions 23H2, 24H2, 26H1 on x64 or ARM64 systems) should prioritize this patch, especially if these systems provide remote access for operational or engineering purposes.
How it could be exploited
An attacker must establish an authenticated Remote Desktop connection to the target system over the network, then trigger the use-after-free condition to execute arbitrary code with the privileges of the RDS service.
Prerequisites
- Valid credentials to access Remote Desktop Services
- Network connectivity to the RDS port (typically 3389)
- Ability to establish an authenticated RDS session
- User interaction may be required to trigger the vulnerability
remotely exploitablerequires authenticationhigh impact on confidentiality and integrity
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (10)
10 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1HARDENINGRestrict Remote Desktop Services network access to authorized engineering workstations and administrative networks using firewall rules
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply Microsoft's September 2026 security update to all affected Windows systems
Long-term hardening
0/1HARDENINGEnforce strong authentication for Remote Desktop Services, including multi-factor authentication where possible
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/fda8aebe-bf8f-4b9a-8423-508c1a99b889Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.