Windows TCP/IP Security Feature Bypass Vulnerability

Plan PatchCVSS 7.5CVE-2026-69793Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Improper validation of TCP/IP input in Windows allows an unauthorized attacker to bypass a security feature over a network. The TCP/IP stack fails to properly validate consistency in incoming packet data, allowing malformed traffic to bypass security checks. Exploitation is currently assessed as unlikely. Affected versions include Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 across 32-bit, x64, and ARM64 architectures.

What this means
What could happen
An attacker on your network could bypass Windows TCP/IP security checks, potentially allowing malformed network traffic to reach systems that should be protected by TCP/IP validation rules.
Who's at risk
Windows and Windows Server administrators managing systems running Windows 10 versions 1607, 1809, 21H2, or 22H2; Windows 11 versions 23H2, 24H2, 25H2, or 26H1; or Windows Server 2016, 2019, 2022, or 2025. Any utility or industrial facility running these operating systems as HMI hosts, engineering workstations, or server infrastructure could be affected.
How it could be exploited
An attacker sends specially crafted TCP/IP packets over the network that contain inconsistent or malformed data. The vulnerable TCP/IP stack fails to properly validate this input, allowing the packets to bypass security feature checks that would normally block or reject them.
Prerequisites
  • Network access to the Windows system
  • Ability to send crafted network packets to the target system
remotely exploitablelow complexityno authentication requiredaffects network security validation
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/11
Schedule — requires maintenance window
0/10

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33438 or later
All products
HOTFIXUpdate Windows 10 Version 1809 32-bit systems to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 1809 x64-based systems to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 21H2 to Build 10.0.19044.7725 or later
HOTFIXUpdate Windows 10 Version 22H2 to Build 10.0.19045.7725 or later
HOTFIXUpdate Windows 11 Version 23H2 to Build 10.0.22631.7582 or later
HOTFIXUpdate Windows 11 Version 24H2 to Build 10.0.26100.9445 or later
HOTFIXUpdate Windows 11 Version 25H2 to Build 10.0.26200.9445 or later
Long-term hardening
0/1
HARDENINGRestrict inbound network access at your firewall to only trusted sources and required services
API: /api/v1/advisories/64186d47-7080-431b-8105-755c1fdbcbe4

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows TCP/IP Security Feature Bypass Vulnerability | CVSS 7.5 - OTPulse