ZeroHour

CVE-2026-69329

large

Unauthenticated out-of-bounds read DoS in Microsoft Windows BranchCache

CVSS 3.1
7.5 high
EPSS
1%p62
Published
()
Modified
AI analysis

CVE-2026-69329 is an out-of-bounds read (CWE-125, arising from an integer-overflow condition, CWE-190) in the BranchCache component of Microsoft Windows. A remote, unauthenticated attacker can trigger the flaw over the network with no privileges or user interaction by sending malformed input to a system running BranchCache. Successful exploitation results only in denial of service of the BranchCache service — availability impact with no information disclosure or tampering (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Affected systems are Windows installations with the optional BranchCache feature enabled, such as branch-office caching deployments (Hosted Cache Servers or clients in distributed mode); the provided data does not specify affected version ranges. There is currently no known exploitation: the flaw was addressed in Microsoft's September 2026 Patch Tuesday (part of a 966-flaw release), has no public PoC, is not in CISA KEV, and carries an EPSS of 1.1% (62nd percentile).

What to do: Apply the September 2026 Microsoft cumulative updates (Windows client and Windows Server) on all systems, prioritizing servers that use BranchCache, such as Hosted Cache Servers and file/web servers behind it. Until patched, mitigate by disabling BranchCache via Group Policy/Windows Features or by restricting network reachability of BranchCache-enabled endpoints. Inventory which systems actually have BranchCache enabled (e.g., via the BranchCache status cmdlets or Group Policy settings) to focus remediation.

Affected
Microsoft Windows BranchCache (component of Windows client and Windows Server)
Estimated exposure
large≈100,000–1,000,000 Windows systems with BranchCache enabled (estimate; total Windows installed base exceeds 1B devices) — BranchCache ships with supported Windows releases but is a non-default, optional feature used mainly for enterprise branch-office WAN caching, so the estimate applies a low enablement rate to the very large Windows device base; this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in BranchCache allows an unauthorized attacker to deny service over a network.

Weakness
CWE-125, CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Microsoft's September 2026 Patch Tuesday fixes a record 966 flaws, including two Windows zero-days actively exploited to gain SYSTEM privileges.

Microsoft's September 2026 Patch Tuesday addresses a record 966 vulnerabilities, including 105 rated Critical, 81 of them remote code execution bugs. Two zero-days were actively exploited: a Windows Update Stack link-following flaw and a Windows ALPC heap-based buffer overflow, both allowing local elevation to SYSTEM privileges. The ALPC flaw was reported by Volexity and Proofpoint researchers, while the Update Stack flaw was credited to Romain Deperne and the Microsoft Threat Intelligence Centre. Microsoft shared no details on how the flaws were exploited in attacks.

BleepingComputer · 7d agoAdvisory in the wildCVE-2026-69805CVE-2026-58649CVE-2026-69806+27 CVEs1