ZeroHour

CVE-2026-69598

mass

Buffer size miscalculation RCE in Microsoft Windows iSCSI

CVSS 3.1
8.8 high
EPSS
<1%p56
Published
()
Modified
AI analysis

CVE-2026-69598 is an incorrect calculation of buffer size (CWE-131) in the Windows iSCSI component, which Microsoft rates as letting an unauthorized (unauthenticated) attacker execute code over a network. The flaw is reached through network processing of iSCSI traffic; the CVSS vector (AV:N, PR:N, UI:R) indicates no privileges or special conditions are needed but user interaction is required, consistent with an attack that depends on an iSCSI connection or session being initiated. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 8.8, High). Affected systems are Windows installations running the affected iSCSI component; the source data does not include specific affected version ranges. Exploitation has not been observed: the CVE is not in CISA's KEV, no public proof-of-concept is known, and EPSS estimates only a ~0.8% probability of exploitation within 30 days (56th percentile).

What to do: Apply Microsoft's security update for CVE-2026-69598 as soon as it is available and confirm your Windows builds against the affected-version list in Microsoft's advisory (ranges are not included in this feed). Until patched, restrict iSCSI traffic (TCP 3260) to trusted networks/hosts and audit whether the MSiSCSI initiator service or the iSCSI Target Server role is enabled on network-reachable Windows systems. Prioritize systems where iSCSI is actively used or exposed, as those are the realistically reachable targets.

Affected
Microsoft Windows iSCSI
Estimated exposure
masshundreds of millions of devices ship the affected component (the iSCSI initiator is included with Windows clients and servers), though systems practically… — The Microsoft iSCSI initiator/service is present by default across the Windows installed base (on the order of a billion-plus Windows devices in use), so the potential fleet is mass-scale, while actual network exposure is concentrated in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network.

Weakness
CWE-131
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.