CVE-2026-73009
largeUse-After-Free RCE in Microsoft Windows SSTP VPN Service
CVE-2026-73009 is a use-after-free (CWE-416) in the Windows Secure Socket Tunneling Protocol (SSTP), Microsoft's SSL/TLS-based VPN protocol. A remote, unauthenticated attacker can trigger the flaw over the network by connecting to the SSTP service, causing it to reuse freed memory in a way that allows arbitrary code execution. Successful exploitation yields code execution on the target system with the privileges of the SSTP/VPN service, with high impact on confidentiality, integrity, and availability (CVSS 9.8). Systems are affected when the SSTP VPN component is enabled — most commonly Windows machines acting as VPN endpoints via the Routing and Remote Access Service — though the data does not specify exact affected version ranges. There is currently no known exploitation, no public proof-of-concept, and the flaw is not in CISA's KEV; EPSS estimates roughly a 0.9% chance of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-73009 as soon as it is available, consulting the Microsoft advisory for the exact affected product/version list. In the interim, inventory for systems with SSTP/RRAS enabled and reduce exposure by blocking or restricting inbound TCP 443 to the SSTP endpoint at the firewall, or fronting it with a patched gateway. Prioritize patching internet-facing VPN servers, since no authentication is required for exploitation.
| Microsoft Windows Secure Socket Tunneling Protocol (SSTP) — VPN service (typically via Routing and Remote Access Service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.