Junglewise Threat Intelligence

CVE-2026-73025: Microsoft Windows iSCSI weak authentication bypass

CVE-2026-73025 · Severity: critical · CVSS 9.8 · Published 2026-09-08

Executive brief

Windows iSCSI (a storage networking protocol) contains a weak authentication mechanism that allows an attacker on the network to bypass its security protections. An attacker exploiting this flaw could gain unauthorized access to iSCSI storage resources, potentially exposing or compromising critical data and infrastructure that depends on these storage connections.

Technical details

The vulnerability exists in Windows iSCSI's authentication implementation, allowing an attacker to bypass security features through weak authentication mechanisms. The flaw is remotely exploitable over the network without requiring prior authentication or user interaction. An attacker can leverage this to gain unauthorized access to iSCSI targets and connected storage resources. The vulnerability is classified as critical with a CVSS score of 9.8, indicating severe impact. Microsoft has released security updates to address this weakness.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats