Windows NTFS Remote Code Execution Vulnerability
MonitorCVSS 6.8CVE-2026-69566Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorPhysical
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Heap-based buffer overflow in Windows NTFS file system allows an attacker with physical access to a computer to execute arbitrary code with the privileges of the system.
What this means
What could happen
An attacker with physical access to a Windows computer could execute malicious code with system privileges, potentially compromising the integrity of SCADA or HMI systems that rely on Windows platforms.
Who's at risk
Water utilities and electric utilities running Windows-based SCADA servers, HMI workstations, or engineering stations should apply this patch. Affects Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 across all CPU architectures.
How it could be exploited
The attack requires physical access to the computer and involves crafting a malicious NTFS file or disk structure. When the Windows system processes the malformed NTFS data, the heap buffer overflow is triggered, allowing code execution at system level.
Prerequisites
- Physical access to the Windows computer
- Ability to present a malicious storage device or modify the NTFS file system on an attached disk
Remotely exploitable requires physical accessNo authentication required for exploitationLow complexity attackHigh impact on confidentiality and integrityAffects multiple Windows versions widely deployed in OT environments
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Do now
0/2HARDENINGRestrict physical access to SCADA servers, HMI workstations, and engineering stations; secure USB ports and restrict media insertion
HARDENINGDisable USB device auto-run and external media auto-mount on critical Windows OT systems
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXApply the September 2026 Windows Server security updates to all Windows Server 2016, 2019, 2022, and 2025 installations
All products
HOTFIXApply the September 2026 Windows security updates to all Windows 10 and Windows 11 systems (see fixed versions by build number in affected products)
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/48196f0c-0e58-411a-bae6-86f6e95ee9a6Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.