Unauthenticated RCE in Microsoft Windows Routing and Remote Access Service (RRAS)
AI analysis
CVE-2026-69590 is a heap-based buffer overflow (CWE-122) in the Windows Routing and Remote Access Service (RRAS) that allows remote code execution, rated 9.8 Critical with a network attack vector requiring no privileges or user interaction. An attacker can trigger the flaw by sending crafted network traffic to a system running the RRAS service, and successful exploitation grants unauthorized access and code execution on the victim machine with high impact to confidentiality, integrity, and availability. Affected systems are Windows machines with the RRAS role/service enabled, typically servers used as VPN endpoints, routers, or NAT gateways; the specific affected Windows version ranges are not specified in the available data. The flaw was addressed in Microsoft's September 2026 Patch Tuesday release (September 8, 2026). There is no known exploitation in the wild, no public proof-of-concept, and it is not in CISA KEV, with EPSS estimating only a 1.0% chance of exploitation within 30 days (60th percentile).
What to do: Apply the September 2026 (Sep 8, 2026) Windows security updates on all systems with the Routing and Remote Access Service enabled, prioritizing internet-facing VPN and routing servers. As an interim mitigation, restrict exposure of RRAS-related ports (e.g., TCP 1723 and related VPN traffic) to trusted networks or disable the RRAS role if it is not in use. Inventory systems for the RRAS role before patching, since the service is off by default on most Windows installations.
Affected
| Microsoft Windows Routing and Remote Access Service (RRAS) | — |
Estimated exposure
largeorder of 10^5 internet-exposed Windows RRAS/PPTP endpoints (a subset of the several hundred thousand hosts seen in public scans of TCP 1723), plus an unknown… — RRAS is not enabled by default and is mostly used on Windows Servers acting as VPN or routing/NAT gateways, so the exposed population is estimated from internet-wide scan data for TCP 1723 (PPTP), where hundreds of thousands of hosts,…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.