CVE-2026-69881
Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
- EPSS probability
- 1.20%
- CWE
- CWE-476
- Published
- 2026-09-08
- Last modified
- 2026-09-11
Affected products
- Microsoft Windows 10 Version 1809
- Microsoft Windows 10 Version 21H2
- Microsoft Windows 10 Version 22H2
- Microsoft Windows 11 version 23H2
- Microsoft Windows 11 Version 23H2
- Microsoft Windows 11 Version 24H2
- Microsoft Windows 11 Version 25H2
- Microsoft Windows 11 version 26H1
Weakness type
Related vulnerabilities
- CVE-2026-78130 — strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute...
- CVE-2026-78126 — strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.
- CVE-2026-45747 — Suricata lua/tls: null dereference in TlsGetCertInfo
- CVE-2026-86547 — mrubyc through 4.0.0 NULL Pointer Dereference via OP_ENTER
- CVE-2026-66303 — Skype for Business and Lync Denial of Service Vulnerability
- CVE-2026-77901 — Microsoft Office Word Remote Code Execution Vulnerability
- CVE-2026-70575 — Windows Schannel Denial of Service Vulnerability
- CVE-2026-69384 — Virtual Hard Disk (VHD) Miniport Driver Denial of Service Vulnerability