Junglewise Threat Intelligence

CVE-2026-70570: Microsoft Windows Routing and Remote Access Service remote code execution

CVE-2026-70570 · Severity: high · CVSS 7.5 · Published 2026-09-08

Executive brief

Windows Routing and Remote Access Service (RRAS) is a core networking component that enables secure remote connections to corporate networks. A remote code execution vulnerability allows an attacker to execute arbitrary code on affected systems without authentication, potentially leading to full system compromise, data theft, and lateral movement within networks.

Technical details

This is a remote code execution vulnerability in the Windows Routing and Remote Access Service (RRAS) component. The vulnerability allows unauthenticated network-based exploitation, meaning an attacker can trigger the flaw over the network without requiring valid credentials or prior access to the system. Successful exploitation results in arbitrary code execution with SYSTEM privileges, enabling complete system takeover. The attack vector is network-based and does not require user interaction. Patches should be available through Microsoft's security update channels.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats