CVE-2026-73025
largeUnauthenticated Security Feature Bypass via Weak Authentication in Windows iSCSI
CVE-2026-73025 is a weak-authentication flaw (CWE-1390) in the iSCSI functionality shipped with Microsoft Windows, rated critical (CVSS 3.1: 9.8) because it is reachable over a network without credentials, special conditions, or user interaction. An unauthorized attacker with network access to the affected iSCSI service can exploit the flawed authentication handling to bypass an intended security feature. Per the CVSS impact metrics, successful exploitation yields high confidentiality, integrity, and availability impact on the affected system. Any organization running Windows systems that use iSCSI — for example, servers hosting iSCSI targets or clients mounting iSCSI storage — is potentially affected, though only systems where the iSCSI service is network-reachable are practically exposed. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns a ~0.9% 30-day exploitation probability (58th percentile), so no confirmed in-the-wild exploitation is known.
What to do: Inventory your Windows estate for iSCSI use (iSCSI Initiator sessions, the iSCSI Target Server role, and exposure of TCP port 3260) and prioritize those hosts for remediation per Microsoft's advisory, since the affected builds are not specified in this data. As an interim mitigation, restrict iSCSI traffic (TCP 3260) to trusted internal network segments and never expose it directly to the internet. With no public PoC, no KEV listing, and EPSS at ~0.9%, near-term exploitation risk appears low, but the critical 9.8 CVSS warrants prompt patching once Microsoft publishes the fix.
| Microsoft Windows iSCSI | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.
- Weakness
- CWE-1390
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.