ZeroHour

CVE-2026-69852

moderate

Heap buffer overflow RCE in Windows Routing and Remote Access Service (RRAS)

CVSS 3.1
7.5 high
EPSS
<1%p49
Published
()
Modified
AI analysis

CVE-2026-69852 is a heap-based buffer overflow (CWE-122) in the Windows Routing and Remote Access Service (RRAS) that allows remote code execution, letting an attacker gain unauthorized access to the victim's machine. Per the CVSS vector, the flaw is reachable over the network (AV:N) but requires low privileges (PR:L) — i.e., some degree of valid access to the RRAS-enabled host — and is rated high attack complexity (AC:H), making successful exploitation non-trivial. Attackers who exploit it gain code execution on the target, with high impact on confidentiality, integrity, and availability. Exposure is limited to Windows systems where RRAS is enabled, typically Windows Server machines configured as routers, NAT gateways, or VPN endpoints; Microsoft addressed the issue in the September 2026 Patch Tuesday security updates. There is currently no known public proof-of-concept, the CVE is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.6% (48th percentile), indicating no observed exploitation activity so far.

What to do: Prioritize applying Microsoft's September 2026 security updates on any host with the Routing and Remote Access service or role enabled — inventory Windows Servers acting as VPN concentrators, NAT gateways, or routers first. Until patched, restrict network access to RRAS endpoints to trusted networks and audit which low-privileged accounts can reach the service, since exploitation requires network reachability plus some valid access. Monitor vendor advisories for the corrected build numbers applicable to your Windows versions.

Affected
Microsoft Windows Routing and Remote Access Service (RRAS) — Windows systems with the RRAS role/service enabled (commonly Windows
Estimated exposure
moderatelikely tens of thousands of RRAS-enabled Windows hosts worldwide, with internet-exposed RRAS/VPN endpoints probably in the low thousands — RRAS is an optional Windows role (used mainly for legacy VPN, routing, or NAT) that is not enabled by default, so affected systems are a small fraction of the very large Windows install base, and public port scans of RRAS-associated…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including 113 critical, with two Windows privilege-escalation bugs (CVE-2026-81963, CVE-2026-85880) exploited in the wild.

Microsoft's September 2026 security update addresses 973 vulnerabilities across its product lineup, 113 rated critical, of which 82 are remote code execution flaws. Two vulnerabilities are confirmed exploited in the wild: CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack (CVSS 7.8), and CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (CVSS 7.8). Microsoft flags several bugs as more likely to be exploited, including a 9.8 RCE in Windows DNS Server (CVE-2026-69730), an 8.8 RCE in Windows Kerberos (CVE-2026-69676), and a 9.0 EoP in Spring Cloud Azure (CVE-2026-69854). Cisco Talos published accompanying Snort rules to detect exploitation attempts against the prominent flaws.

Cisco Talos · 7d agoAdvisory in the wildCVE-2026-81963CVE-2026-85880CVE-2026-69676+27 CVEs

Microsoft Patch Tuesday, September 2026 Security Update Review

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, including 113 critical and two actively exploited Windows privilege escalation flaws.

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, its largest release ever, including 113 critical and 860 important, covering Windows HTTP.sys, Hyper-V, Entra ID, Exchange Server, Office, DNS, and more. Two zero-days are confirmed exploited in the wild: CVE-2026-81963 (Windows Update Stack EoP) and CVE-2026-85880 (ALPC heap overflow), both letting authenticated attackers gain SYSTEM privileges. Notable criticals include an Entra ID authentication bypass (CVE-2026-62916) and multiple Windows DNS Server and Office remote code execution flaws.