ZeroHour

CVE-2026-72959

large

Authenticated RCE in Windows Routing and Remote Access Service (RRAS)

CVSS 3.1
8.8 high
EPSS
<1%p57
Published
()
Modified
AI analysis

CVE-2026-72959 is a heap-based buffer overflow (CWE-122) in Windows' Routing and Remote Access Service (RRAS) that can lead to remote code execution. It is triggered by sending crafted network traffic to the RRAS service on an affected host; per the CVSS vector, exploitation is network-based with low attack complexity, requires only low-privileged (authenticated) credentials, and needs no user interaction. A successful attacker gains the ability to execute code on the victim's machine and obtain unauthorized access, with high impact on confidentiality, integrity, and availability. Affected systems are Windows hosts with the RRAS role/service enabled, most commonly servers acting as VPN/remote-access gateways or routers. The flaw was disclosed in Microsoft's September 2026 Patch Tuesday; it is not yet in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.9% chance of exploitation within 30 days, so exploitation is plausible but not yet widely observed.

What to do: Apply the September 2026 Microsoft security updates (Patch Tuesday) as soon as possible on any Windows machine with the Routing and Remote Access role/service enabled. Inventory for RRAS in use (e.g., servers terminating VPN connections or acting as routers), restrict RRAS/VPN ports to trusted networks via firewall rules, and monitor Microsoft's advisory for the confirmed list of affected Windows versions.

Affected
Microsoft Windows Routing and Remote Access Service (RRAS)
Estimated exposure
large≈100,000+ Windows Server hosts with RRAS enabled, of which tens of thousands are internet-exposed VPN/routing endpoints — RRAS is not installed by default on Windows Server and is enabled mainly as VPN/remote-access gateways and routing servers, while public internet scans of typical RRAS/VPN endpoints (e.g., PPTP port 1723) consistently show tens of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including 113 critical, with two Windows privilege-escalation bugs (CVE-2026-81963, CVE-2026-85880) exploited in the wild.

Microsoft's September 2026 security update addresses 973 vulnerabilities across its product lineup, 113 rated critical, of which 82 are remote code execution flaws. Two vulnerabilities are confirmed exploited in the wild: CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack (CVSS 7.8), and CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (CVSS 7.8). Microsoft flags several bugs as more likely to be exploited, including a 9.8 RCE in Windows DNS Server (CVE-2026-69730), an 8.8 RCE in Windows Kerberos (CVE-2026-69676), and a 9.0 EoP in Spring Cloud Azure (CVE-2026-69854). Cisco Talos published accompanying Snort rules to detect exploitation attempts against the prominent flaws.

Cisco Talos · 7d agoAdvisory in the wildCVE-2026-81963CVE-2026-85880CVE-2026-69676+27 CVEs

Microsoft Patch Tuesday, September 2026 Security Update Review

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, including 113 critical and two actively exploited Windows privilege escalation flaws.

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, its largest release ever, including 113 critical and 860 important, covering Windows HTTP.sys, Hyper-V, Entra ID, Exchange Server, Office, DNS, and more. Two zero-days are confirmed exploited in the wild: CVE-2026-81963 (Windows Update Stack EoP) and CVE-2026-85880 (ALPC heap overflow), both letting authenticated attackers gain SYSTEM privileges. Notable criticals include an Entra ID authentication bypass (CVE-2026-62916) and multiple Windows DNS Server and Office remote code execution flaws.