ZeroHour

CVE-2026-72950

large

Heap Buffer Overflow RCE in Windows Routing and Remote Access Service (RRAS)

CVSS 3.1
8.8 high
EPSS
<1%p57
Published
()
Modified
AI analysis

Microsoft's Routing and Remote Access Service (RRAS) contains a heap-based buffer overflow (CWE-122) that permits remote code execution on the host running the service. An attacker can trigger the flaw by sending crafted network requests to the RRAS service, such as on a server configured as a VPN, dial-in, or routing endpoint; the CVSS vector (AV:N/PR:L/UI:N) indicates the attacker needs low-privilege access and no user interaction is required. Successful exploitation yields code execution with high confidentiality, integrity, and availability impact, giving the attacker unauthorized access to the victim machine. Only systems with RRAS enabled are affected — typically Windows Servers acting as VPN or remote-access/routing endpoints — because the role is optional and not installed by default. As of the September 2026 Patch Tuesday release there are no reports of in-the-wild exploitation, no known public proof-of-concept, and the CVE is not in CISA's KEV catalog, with EPSS estimating roughly a 0.9% probability of exploitation within 30 days.

What to do: Apply Microsoft's September 2026 Patch Tuesday security updates to all systems running RRAS, prioritizing internet-facing VPN and remote-access servers. Inventory your environment for servers with the Remote Access/RRAS role enabled and restrict network access to those endpoints until patched. No public exploit is known, but monitor for PoC releases given the history of exploitable RRAS vulnerabilities.

Affected
Microsoft Windows Routing and Remote Access Service (RRAS)
Estimated exposure
large≈10,000–100,000 internet-exposed Windows servers with RRAS enabled (estimate; more may exist on internal networks) — RRAS is an optional Windows Server role used mainly for VPN and LAN routing and is not enabled by default, so only a fraction of the very large installed base of Windows Servers runs it; internet-exposed Windows VPN/remote-access endpoints…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday, September 2026 Security Update Review

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, including 113 critical and two actively exploited Windows privilege escalation flaws.

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, its largest release ever, including 113 critical and 860 important, covering Windows HTTP.sys, Hyper-V, Entra ID, Exchange Server, Office, DNS, and more. Two zero-days are confirmed exploited in the wild: CVE-2026-81963 (Windows Update Stack EoP) and CVE-2026-85880 (ALPC heap overflow), both letting authenticated attackers gain SYSTEM privileges. Notable criticals include an Entra ID authentication bypass (CVE-2026-62916) and multiple Windows DNS Server and Office remote code execution flaws.