CVE-2026-69461
massStack-Based Buffer Overflow in Windows NTFS Enables Network RCE
CVE-2026-69461 is a stack-based buffer overflow (CWE-121) in the NTFS component of Microsoft Windows that can allow an unauthorized (unauthenticated) attacker to execute arbitrary code over a network. Per Microsoft's advisory, the flaw is remotely reachable and requires no privileges, though the CVSS vector indicates user interaction is needed to trigger it, suggesting exploitation depends on a user handling attacker-influenced input processed by NTFS. A successful attack yields code execution on the victim machine with high impact to confidentiality, integrity, and availability. Potentially every Windows system running the vulnerable NTFS code is affected, but Microsoft has not published specific affected version ranges in the data available here. There is no evidence of exploitation in the wild, no known public proof-of-concept, and the issue is not on CISA's KEV list; EPSS currently assigns a 0.8% probability of exploitation within 30 days.
What to do: Install the Microsoft security update for CVE-2026-69461 via Windows Update as soon as it is available and confirm your build is listed in Microsoft's advisory, since affected version ranges are not specified here. Until patched, limit exposure by avoiding opening or mounting untrusted files, disk images, or content from remote/untrusted sources that would be processed by NTFS, and monitor Microsoft's bulletin for updates on affected versions and any exploitation reports.
| Microsoft Windows (NTFS component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Stack-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.