Junglewise Threat Intelligence

CVE-2026-65796: Microsoft Windows iSCSI Target Service heap-based buffer overflow

CVE-2026-65796 · Severity: high · CVSS 8.1 · Published 2026-08-11

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows iSCSI Target Service is a network storage protocol handler used in enterprise environments to enable remote data access. A heap-based buffer overflow in this service allows an attacker on the network to execute arbitrary code with elevated privileges, potentially compromising the entire system and any data accessed through it.

Technical details

A heap-based buffer overflow vulnerability exists in the Windows iSCSI Target Service that processes network iSCSI protocol messages. The vulnerability can be triggered by an unauthenticated attacker sending a specially crafted network packet to the iSCSI service, allowing remote code execution without authentication. The attack vector is network-based and does not require user interaction or prior system access. An attacker can exploit this to gain code execution context on the affected system. A patch is available through Microsoft security updates.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-08-11: disclosed

References

Related threats