CVE-2026-69598
massBuffer size miscalculation RCE in Microsoft Windows iSCSI
CVE-2026-69598 is an incorrect calculation of buffer size (CWE-131) in the Windows iSCSI component, which Microsoft rates as letting an unauthorized (unauthenticated) attacker execute code over a network. The flaw is reached through network processing of iSCSI traffic; the CVSS vector (AV:N, PR:N, UI:R) indicates no privileges or special conditions are needed but user interaction is required, consistent with an attack that depends on an iSCSI connection or session being initiated. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 8.8, High). Affected systems are Windows installations running the affected iSCSI component; the source data does not include specific affected version ranges. Exploitation has not been observed: the CVE is not in CISA's KEV, no public proof-of-concept is known, and EPSS estimates only a ~0.8% probability of exploitation within 30 days (56th percentile).
What to do: Apply Microsoft's security update for CVE-2026-69598 as soon as it is available and confirm your Windows builds against the affected-version list in Microsoft's advisory (ranges are not included in this feed). Until patched, restrict iSCSI traffic (TCP 3260) to trusted networks/hosts and audit whether the MSiSCSI initiator service or the iSCSI Target Server role is enabled on network-reachable Windows systems. Prioritize systems where iSCSI is actively used or exposed, as those are the realistically reachable targets.
| Microsoft Windows iSCSI | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-131
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.