AI analysis
Microsoft's Routing and Remote Access Service (RRAS) contains a heap-based buffer overflow (CWE-122) that permits remote code execution on the host running the service. An attacker can trigger the flaw by sending crafted network requests to the RRAS service, such as on a server configured as a VPN, dial-in, or routing endpoint; the CVSS vector (AV:N/PR:L/UI:N) indicates the attacker needs low-privilege access and no user interaction is required. Successful exploitation yields code execution with high confidentiality, integrity, and availability impact, giving the attacker unauthorized access to the victim machine. Only systems with RRAS enabled are affected — typically Windows Servers acting as VPN or remote-access/routing endpoints — because the role is optional and not installed by default. As of the September 2026 Patch Tuesday release there are no reports of in-the-wild exploitation, no known public proof-of-concept, and the CVE is not in CISA's KEV catalog, with EPSS estimating roughly a 0.9% probability of exploitation within 30 days.
What to do: Apply Microsoft's September 2026 Patch Tuesday security updates to all systems running RRAS, prioritizing internet-facing VPN and remote-access servers. Inventory your environment for servers with the Remote Access/RRAS role enabled and restrict network access to those endpoints until patched. No public exploit is known, but monitor for PoC releases given the history of exploitable RRAS vulnerabilities.
Affected
| Microsoft Windows Routing and Remote Access Service (RRAS) | — |
Estimated exposure
large≈10,000–100,000 internet-exposed Windows servers with RRAS enabled (estimate; more may exist on internal networks) — RRAS is an optional Windows Server role used mainly for VPN and LAN routing and is not enabled by default, so only a fraction of the very large installed base of Windows Servers runs it; internet-exposed Windows VPN/remote-access endpoints…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.