Junglewise Threat Intelligence

CVE-2026-68898: Microsoft Windows iSCSI out-of-bounds read

CVE-2026-68898 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Vendors: Microsoft.

Executive brief

Windows iSCSI is a network protocol used for storage connectivity. An attacker can exploit an out-of-bounds read vulnerability in the iSCSI implementation to cause the system to crash or become unresponsive, disrupting network storage access and potentially causing service outages.

Technical details

An out-of-bounds read vulnerability exists in the Windows iSCSI subsystem that allows an unauthenticated attacker to send a specially crafted network packet triggering a memory access violation. The vulnerability can be exploited over the network without prior authentication. A successful exploit results in denial of service through system crash or hang, disrupting iSCSI storage connectivity and availability. A patch has been published by Microsoft to address this issue.

Affected products

  • Microsoft Windows iSCSI <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats