Junglewise Threat Intelligence

CVE-2026-69428: Microsoft Windows LDAP out-of-bounds read

CVE-2026-69428 · Severity: high · CVSS 7.5 · Published 2026-09-08

Executive brief

Windows LDAP (Lightweight Directory Access Protocol) is a critical component used to authenticate users and manage directory services in enterprise networks. An out-of-bounds read vulnerability allows an attacker on the network to cause a denial of service, disrupting authentication services and potentially affecting business operations that depend on directory access.

Technical details

An out-of-bounds read vulnerability exists in the Windows LDAP implementation, allowing an attacker to read memory beyond allocated buffer boundaries. The vulnerability can be triggered remotely over the network without requiring authentication. Exploitation results in a denial-of-service condition through service crash or hang. A patch from Microsoft is expected to be available through standard security updates.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats