AI analysis
CVE-2026-69329 is an out-of-bounds read (CWE-125, arising from an integer-overflow condition, CWE-190) in the BranchCache component of Microsoft Windows. A remote, unauthenticated attacker can trigger the flaw over the network with no privileges or user interaction by sending malformed input to a system running BranchCache. Successful exploitation results only in denial of service of the BranchCache service — availability impact with no information disclosure or tampering (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Affected systems are Windows installations with the optional BranchCache feature enabled, such as branch-office caching deployments (Hosted Cache Servers or clients in distributed mode); the provided data does not specify affected version ranges. There is currently no known exploitation: the flaw was addressed in Microsoft's September 2026 Patch Tuesday (part of a 966-flaw release), has no public PoC, is not in CISA KEV, and carries an EPSS of 1.1% (62nd percentile).
What to do: Apply the September 2026 Microsoft cumulative updates (Windows client and Windows Server) on all systems, prioritizing servers that use BranchCache, such as Hosted Cache Servers and file/web servers behind it. Until patched, mitigate by disabling BranchCache via Group Policy/Windows Features or by restricting network reachability of BranchCache-enabled endpoints. Inventory which systems actually have BranchCache enabled (e.g., via the BranchCache status cmdlets or Group Policy settings) to focus remediation.
Affected
| Microsoft Windows BranchCache (component of Windows client and Windows Server) | — |
Estimated exposure
large≈100,000–1,000,000 Windows systems with BranchCache enabled (estimate; total Windows installed base exceeds 1B devices) — BranchCache ships with supported Windows releases but is a non-default, optional feature used mainly for enterprise branch-office WAN caching, so the estimate applies a low enablement rate to the very large Windows device base; this is an…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.