CVE-2026-69496
massHeap Buffer Overflow RCE in Windows Compressed Folder (CVSS 9.8)
CVE-2026-69496 is a heap-based buffer overflow (CWE-122) in the Windows Compressed Folder feature, the built-in Windows component that handles compressed archives. According to the CVSS vector, it is reachable over a network by an unauthorized attacker with no privileges and no user interaction, meaning an attacker can potentially trigger the flaw by sending crafted data to affected code without credentials. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability. Any Windows system that includes the Compressed Folder feature is affected; Microsoft has not specified the exact vulnerable version ranges in the provided data. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 1.0% probability of exploitation in the next 30 days.
What to do: Apply Microsoft's security update for CVE-2026-69496 as soon as it is released via Windows Update, prioritizing internet-facing and shared systems, and check Microsoft's advisory for the exact affected version ranges since none were provided here. Until patched, review whether any systems expose archive-parsing functionality to untrusted network input and monitor for emerging PoCs given the critical network-RCE score. With no public exploit and a low EPSS (1.0%), immediate risk appears limited, but the AV:N/PR:N/UI:N vector makes prompt patching prudent.
| Microsoft Windows (Compressed Folder feature) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.