Junglewise Threat Intelligence

CVE-2026-69839: Microsoft Windows iSCSI Target Service uncaught exception denial of service

CVE-2026-69839 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Executive brief

Windows iSCSI Target Service is a network storage protocol handler used in enterprise environments. An authorized attacker can trigger an uncaught exception in this service, causing it to crash and deny service to legitimate users accessing iSCSI storage resources over the network.

Technical details

The vulnerability is an uncaught exception in the Windows iSCSI Target Service that can be triggered by an authenticated attacker over the network. The flaw allows an attacker with valid credentials to send a specially crafted request that causes the service to crash, resulting in denial of service. The attack vector is network-based and requires prior authentication, limiting exposure but still posing operational risk to systems relying on iSCSI storage availability. Microsoft has released security patches to address this issue.

Affected products

  • Microsoft Windows iSCSI Target Service

Timeline

  • 2026-09-08: disclosed

References

Related threats