ZeroHour

CVE-2026-69860

mass

Heap-Based Buffer Overflow in Windows Imaging Component Allows Network RCE

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-69860 is a heap-based buffer overflow (CWE-122) in the Windows Imaging Component, the built-in Windows subsystem responsible for decoding image formats. An unauthenticated remote attacker can trigger the flaw by getting a user to open or preview a specially crafted image file (the CVSS vector is network-based but requires user interaction). Successful exploitation allows arbitrary code execution in the context of the affected user, with high impact on confidentiality, integrity, and availability. Any Windows installation carrying the affected Imaging Component is exposed, and the fix is distributed through Microsoft's September 2026 security updates. There is currently no known in-the-wild exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at roughly 0.8%.

What to do: Deploy Microsoft's September 2026 security updates on all Windows clients and servers as part of this month's Patch Tuesday cycle, prioritizing end-user workstations where users routinely open images from email, the web, or file shares. Until patching is complete, exercise caution with untrusted image files and attachments. Verify that the WIC-related update for CVE-2026-69860 is included in your organization's September 2026 patch compliance reporting.

Affected
Microsoft Windows Imaging Component (component of Windows client and server editions)
Estimated exposure
mass≈1 billion+ Windows devices (WIC is a default component of the Windows operating system) — Windows Imaging Component ships built into Windows client and server editions, so effectively every Windows installation carries the component, and the global Windows installed base is on the order of a billion devices.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday, September 2026 Security Update Review

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, including 113 critical and two actively exploited Windows privilege escalation flaws.

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, its largest release ever, including 113 critical and 860 important, covering Windows HTTP.sys, Hyper-V, Entra ID, Exchange Server, Office, DNS, and more. Two zero-days are confirmed exploited in the wild: CVE-2026-81963 (Windows Update Stack EoP) and CVE-2026-85880 (ALPC heap overflow), both letting authenticated attackers gain SYSTEM privileges. Notable criticals include an Entra ID authentication bypass (CVE-2026-62916) and multiple Windows DNS Server and Office remote code execution flaws.