Junglewise Threat Intelligence

CVE-2026-69590: Microsoft Windows RRAS remote code execution

CVE-2026-69590 · Severity: critical · CVSS 9.8 · Published 2026-09-08

Executive brief

Windows Routing and Remote Access Service (RRAS) is a built-in Windows networking component that handles remote connectivity and VPN operations. A remote code execution vulnerability allows an attacker to execute arbitrary code on a victim's machine without authentication, potentially giving complete system control and enabling theft of sensitive data, installation of malware, or lateral movement within a network.

Technical details

This remote code execution vulnerability in Windows RRAS has a CVSS score of 9.8, indicating a critical severity with network-level attack vector and no authentication or user interaction required. The vulnerability allows an unauthenticated remote attacker to execute arbitrary code on affected Windows systems. Detailed exploitation steps and root cause are not publicly available in the provided reference materials. Microsoft has issued security patches through their standard update channels to address this issue.

Affected products

  • Microsoft Windows RRAS

Timeline

  • 2026-09-08: disclosed

References

Related threats