Junglewise Threat Intelligence

CVE-2026-65681: Microsoft Windows iSCSI Target Service null pointer dereference

CVE-2026-65681 · Severity: high · CVSS 7.5 · Published 2026-08-11

Executive brief

Windows iSCSI Target Service is a Windows component that manages iSCSI storage connections. A null pointer dereference vulnerability allows a network attacker to crash the service and disrupt storage connectivity for affected systems without requiring authentication.

Technical details

This is a null pointer dereference vulnerability in Windows iSCSI Target Service that can be triggered over the network. The vulnerability requires no authentication and can be exploited by sending a specially crafted network request to the iSCSI service. An attacker can cause a denial of service by crashing the service, disrupting iSCSI storage access for dependent applications and systems. Patches are expected to be available from Microsoft.

Affected products

  • Microsoft Windows iSCSI Target Service <UNKNOWN>

Timeline

  • 2026-08-11: disclosed

References

Related threats