ZeroHour

CVE-2026-69881

mass

Null Pointer Dereference DoS in Windows IKE Extension

CVSS 3.1
7.5 high
EPSS
1%p66
Published
()
Modified
AI analysis

CVE-2026-69881 is a null pointer dereference (CWE-476) in the Windows IKE Extension, the built-in Windows component implementing IKE/IPsec key negotiation for VPN and IPsec connectivity. A remote, unauthenticated attacker can trigger the flaw by sending network traffic to the IKE Extension (typically IKE packets to UDP 500/4500) in a way that causes the service to dereference a null pointer. The attacker gains denial of service only: the CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) confirms high availability impact with no confidentiality or integrity loss, likely crashing the IKEEXT service or the host's networking until a restart. All Windows systems carrying the IKE Extension are affected, with the greatest practical risk to hosts that accept inbound IKE traffic, such as VPN gateways, Always On VPN/DirectAccess endpoints, and RRAS servers. There is currently no known exploitation, no public proof-of-conce, and no CISA KEV listing; EPSS estimates a 1.2% chance of exploitation within 30 days.

What to do: Patch via the Microsoft Windows security update that addresses CVE-2026-69881 as soon as it is distributed through Windows Update (no specific KB or version numbers are provided in available data). Prioritize hosts serving VPN roles (Always On VPN, DirectAccess, RRAS, IPsec policy endpoints) and restrict inbound UDP 500/4500 to trusted VPN peers where feasible. Given no known exploitation or public PoC, routine patch-cycle remediation is reasonable for non-exposed endpoints.

Affected
Microsoft Windows IKE Extension
Estimated exposure
masshundreds of millions to ~1B+ Windows devices ship the IKE Extension by default; the network-reachable subset (hosts accepting inbound UDP 500/4500, e.g.,… — The IKEEXT service ships with Windows by default across the roughly 1.5-billion-device Windows installed base, but only systems configured for VPN/IPsec roles and exposed to inbound IKE on UDP 500/4500 are remotely reachable by an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network.

Vendors
microsoft
Products
windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-476
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.