ZeroHour

CVE-2026-73025

large

Unauthenticated Security Feature Bypass via Weak Authentication in Windows iSCSI

CVSS 3.1
9.8 critical
EPSS
<1%p58
Published
()
Modified
AI analysis

CVE-2026-73025 is a weak-authentication flaw (CWE-1390) in the iSCSI functionality shipped with Microsoft Windows, rated critical (CVSS 3.1: 9.8) because it is reachable over a network without credentials, special conditions, or user interaction. An unauthorized attacker with network access to the affected iSCSI service can exploit the flawed authentication handling to bypass an intended security feature. Per the CVSS impact metrics, successful exploitation yields high confidentiality, integrity, and availability impact on the affected system. Any organization running Windows systems that use iSCSI — for example, servers hosting iSCSI targets or clients mounting iSCSI storage — is potentially affected, though only systems where the iSCSI service is network-reachable are practically exposed. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns a ~0.9% 30-day exploitation probability (58th percentile), so no confirmed in-the-wild exploitation is known.

What to do: Inventory your Windows estate for iSCSI use (iSCSI Initiator sessions, the iSCSI Target Server role, and exposure of TCP port 3260) and prioritize those hosts for remediation per Microsoft's advisory, since the affected builds are not specified in this data. As an interim mitigation, restrict iSCSI traffic (TCP 3260) to trusted internal network segments and never expose it directly to the internet. With no public PoC, no KEV listing, and EPSS at ~0.9%, near-term exploitation risk appears low, but the critical 9.8 CVSS warrants prompt patching once Microsoft publishes the fix.

Affected
Microsoft Windows iSCSI
Estimated exposure
large≈100,000–1,000,000 iSCSI-enabled Windows systems (iSCSI initiator/target ships in-box with Windows; only tens of thousands of iSCSI endpoints appear in public… — The iSCSI components ship in-box with Windows desktop and server editions (installed base >1B devices), but only systems actually using iSCSI — typically internal SAN deployments that are rarely exposed on TCP 3260 to the internet — are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.

Weakness
CWE-1390
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.