CVE-2026-69438
massNumeric Type Conversion Flaw in Microsoft JScript Enables Network RCE
Microsoft JScript contains a flaw (CWE-681, incorrect conversion between numeric types) that mishandles a numeric type conversion, and an unauthenticated attacker who can get the engine to process specially crafted input over a network can exploit it to execute code. The attack vector is network-based with no privileges or user interaction required, but the high attack-complexity metric means exploitation depends on conditions the attacker does not fully control. A successful attack yields high impact to confidentiality, integrity, and availability — typically code execution in the context of the process hosting the JScript engine. Affected deployments include any product that bundles the JScript engine, which ships as a component of Microsoft Windows, though the available advisory data does not enumerate specific product versions. Exploitation status: no known exploitation, no public proof-of-concept, not listed in CISA KEV, and EPSS assigns a 0.7% probability of exploitation within 30 days.
What to do: Apply the Microsoft security update for CVE-2026-69438 as soon as it is published, via Windows Update or Microsoft's advisory, and verify patch status across the Windows estate once affected versions are enumerated. Until patched, review where the JScript engine (e.g., Windows Script Host or legacy scripting paths) processes untrusted, network-supplied input and restrict or harden those code paths. Given no known exploitation and no public PoC, routine patch-cadence prioritization is reasonable rather than emergency response.
| Microsoft JScript | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect conversion between numeric types in Microsoft JScript allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-681
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.