CVE-2026-69539
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- EPSS probability
- 0.51%
- CWE
- CWE-416
- Published
- 2026-09-08
- Last modified
- 2026-09-11
Affected products
- Microsoft Windows 10 Version 1607
- Microsoft Windows 10 Version 1809
- Microsoft Windows 10 Version 21H2
- Microsoft Windows 10 Version 22H2
- Microsoft Windows 11 version 23H2
- Microsoft Windows 11 Version 23H2
- Microsoft Windows 11 Version 24H2
- Microsoft Windows 11 Version 25H2
Weakness type
Related vulnerabilities
- CVE-2026-70341 — Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2026-57842 — NetBSD COMPAT_NETBSD32 Double Free / Use-After-Free via recvmsg() msg_iovlen
- CVE-2026-78133 — libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision...
- CVE-2026-45752 — Suricata detect/transform: use-after-free in decompress transforms
- CVE-2026-45751 — Suricata detect/transform: use-after-free in dotprefix transform
- CVE-2026-88032 — Application denial of service via cancellation race in reactive client-side encryption in MongoDB Java Driver
- CVE-2026-87933 — DaveGamble cJSON cJSON_Utils.c cJSONUtils_MergePatch use after free
- CVE-2026-87877 — zstd-jni 1.3.8-4 through 1.5.7-13 Use-After-Free via Setters Called After close()