CVE-2026-69793
massRemote Security Feature Bypass in Microsoft Windows TCP/IP
CVE-2026-69793 is a flaw in the Windows TCP/IP networking stack in which input is not properly validated for internal consistency (CWE-1288), allowing a security feature to be bypassed. A remote, unauthenticated attacker can trigger it by sending crafted network traffic to a vulnerable Windows host; per the CVSS vector, no privileges or user interaction are required. Successful exploitation compromises integrity only: the attacker bypasses a Windows security feature, with no confidentiality or availability impact per the CVSS score. Any Windows system using the TCP/IP stack is potentially affected, which in practice means essentially all Windows desktops and servers, with the exact affected builds listed in Microsoft's advisory. As of this analysis there is no public proof-of-concept, no CISA KEV listing, and no known in-the-wild exploitation, and EPSS estimates a 0.8% probability of exploitation within 30 days.
What to do: Check Microsoft's security advisory for the exact affected and fixed builds and apply the corresponding Windows security update as soon as feasible. Because the flaw is remotely triggerable without authentication, prioritize patching internet-facing Windows hosts (servers exposing RDP, VPN, or other network services). There is no practical workaround for the TCP/IP stack and no known PoC or in-the-wild exploitation, so patching is the primary and only effective mitigation.
| Microsoft Windows TCP/IP (component of Microsoft Windows client and server operating systems) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper validation of consistency within input in Windows TCP/IP allows an unauthorized attacker to bypass a security feature over a network.
- Weakness
- CWE-1288
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.