Junglewise Threat Intelligence

CVE-2026-69598: Microsoft Windows iSCSI buffer overflow

CVE-2026-69598 · Severity: high · CVSS 8.8 · Published 2026-09-08

Vendors: Microsoft.

Executive brief

Windows iSCSI is a storage networking protocol used to connect servers to disk storage over IP networks. An attacker can exploit an incorrect buffer size calculation to execute arbitrary code remotely without authentication, potentially gaining full control of affected systems and compromising sensitive data or disrupting operations.

Technical details

A buffer overflow vulnerability exists in Windows iSCSI due to incorrect calculation of buffer size, allowing remote code execution. The vulnerability is reachable over the network without requiring authentication. An attacker can send a specially crafted iSCSI packet to trigger the buffer overflow and execute arbitrary code with the privileges of the iSCSI service. The attack vector is network-based, and no user interaction is required to exploit the flaw.

Affected products

  • Microsoft Windows iSCSI

Timeline

  • 2026-09-08: disclosed

References

Related threats