ZeroHour

CVE-2026-73010

large

Unauthenticated Use-After-Free RCE in Windows Failover Cluster

CVSS 3.1
9.8 critical
EPSS
<1%p58
Published
()
Modified
AI analysis

CVE-2026-73010 is a use-after-free memory-safety flaw (CWE-416) in the Windows Failover Cluster component, rated critical at CVSS 9.8 with a fully network-based attack vector. An unauthorized remote attacker can trigger the condition by sending network traffic that causes the component to use freed memory, with no privileges or user interaction required. Successful exploitation allows the attacker to execute arbitrary code over the network on the targeted system, with high impact on confidentiality, integrity, and availability. Affected organizations are those running Windows Server with the Failover Clustering feature enabled, particularly where cluster nodes or their service endpoints are reachable from untrusted networks. The flaw was addressed in Microsoft's September 2026 Security Update Review; there is no known public proof-of-concept, it is not yet in CISA's KEV catalog, and EPSS currently estimates only about a 0.9% chance of exploitation in the next 30 days.

What to do: Apply the September 2026 Windows security updates from Microsoft to all cluster nodes, using Microsoft's recommended rolling-update procedure for clusters. Inventory servers with the Failover Clustering feature enabled and restrict network access to cluster service/RPC endpoints so they are not reachable from untrusted networks. Prioritize patching cluster nodes exposed to broader networks, and watch for updated KEV/EPSS signals given the critical severity despite the currently low exploitation probability.

Affected
Microsoft Windows Server (Failover Cluster / Failover Clustering feature)
Estimated exposure
largetens of thousands to low hundreds of thousands of servers with Failover Clustering enabled (exact counts unpublished; internet-exposed subset unknown) — Windows Server has a very large enterprise installed base and Failover Clustering is a standard high-availability feature commonly deployed in data centers, but Microsoft publishes no install counts, so this is an order-of-magnitude…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

The September 2026 Security Update Review

ZDI's September 2026 Microsoft update review lists two already-exploited Windows EoP zero-days and dozens of critical RCEs across Office, SQL Server, and Windows services.

The review catalogs Microsoft's September 2026 fixes, marking CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack) as already exploited elevation-of-privilege issues. It also lists critical RCE flaws in Office, Word, Excel, PowerPoint, Outlook, SQL Server, Windows DNS, DHCP and Failover Cluster, plus graphics component RCEs. Azure-side fixes include Entra ID, Copilot Studio, Azure AI Language and Azure AD B2C elevation-of-privilege flaws.