Windows TCP/IP Security Feature Bypass Vulnerability
Plan PatchCVSS 7.5CVE-2026-69793Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Improper validation of TCP/IP input in Windows allows an unauthorized attacker to bypass a security feature over a network. The TCP/IP stack fails to properly validate consistency in incoming packet data, allowing malformed traffic to bypass security checks. Exploitation is currently assessed as unlikely. Affected versions include Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 across 32-bit, x64, and ARM64 architectures.
What this means
What could happen
An attacker on your network could bypass Windows TCP/IP security checks, potentially allowing malformed network traffic to reach systems that should be protected by TCP/IP validation rules.
Who's at risk
Windows and Windows Server administrators managing systems running Windows 10 versions 1607, 1809, 21H2, or 22H2; Windows 11 versions 23H2, 24H2, 25H2, or 26H1; or Windows Server 2016, 2019, 2022, or 2025. Any utility or industrial facility running these operating systems as HMI hosts, engineering workstations, or server infrastructure could be affected.
How it could be exploited
An attacker sends specially crafted TCP/IP packets over the network that contain inconsistent or malformed data. The vulnerable TCP/IP stack fails to properly validate this input, allowing the packets to bypass security feature checks that would normally block or reject them.
Prerequisites
- Network access to the Windows system
- Ability to send crafted network packets to the target system
remotely exploitablelow complexityno authentication requiredaffects network security validation
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/11
Schedule — requires maintenance window
0/10Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33438 or later
All products
HOTFIXUpdate Windows 10 Version 1809 32-bit systems to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 1809 x64-based systems to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 21H2 to Build 10.0.19044.7725 or later
HOTFIXUpdate Windows 10 Version 22H2 to Build 10.0.19045.7725 or later
HOTFIXUpdate Windows 11 Version 23H2 to Build 10.0.22631.7582 or later
HOTFIXUpdate Windows 11 Version 24H2 to Build 10.0.26100.9445 or later
HOTFIXUpdate Windows 11 Version 25H2 to Build 10.0.26200.9445 or later
Long-term hardening
0/1HARDENINGRestrict inbound network access at your firewall to only trusted sources and required services
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/64186d47-7080-431b-8105-755c1fdbcbe4Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.