Summary
CVE-2026-65791 is a critical heap-based buffer overflow in the Windows iSCSI Target Service. An unauthenticated attacker can send a specially crafted network packet to an affected service and potentially execute code remotely. The vulnerability has a CVSS score of 9.8, with network-based exploitation requiring no privileges or user interaction.
The vulnerability affects Windows 10 Version 1607 and 1809, and Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025. Microsoft has released security updates with specific fixed builds for the affected products.
Urgent Actions Required
- Apply the applicable Microsoft security update and verify that the affected system reaches the corresponding fixed build.
- Prioritize systems running the Windows iSCSI Target Service, particularly those where the service can be reached over the network.
- Restrict iSCSI traffic to known, trusted initiator IP addresses using network access controls where appropriate.
- Monitor iSCSI traffic for unusual packet sizes or connection patterns that could indicate attempted exploitation.
Which Systems Are Vulnerable to CVE-2026-65791?
Technical Overview
- Vulnerability Type: Heap-Based Buffer Overflow (CWE-122)
- Affected Software/Versions:
- Windows 10 Version 1607: below 10.0.14393.9418
- Windows 10 Version 1809: below 10.0.17763.9121
- Windows Server 2012: below 6.2.9200.26280
- Windows Server 2012 R2: below 6.3.9600.23338
- Windows Server 2016: below 10.0.14393.9418
- Windows Server 2019: below 10.0.17763.9121
- Windows Server 2022: below 10.0.20348.5499
- Windows Server 2025: below 10.0.26100.33296
- CVSS Vector: v3.1
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
- Patch Availability: Yes, available
How Does the CVE-2026-65791 Exploit Work?
The attack typically follows these steps:
What Causes CVE-2026-65791?
Vulnerability Root Cause:
CVE-2026-65791 is caused by a heap-based buffer overflow in the Windows iSCSI Target Service. A specially crafted network packet can trigger the flaw, allowing an unauthorized attacker to execute code remotely.
How Can You Mitigate CVE-2026-65791?
If immediate patching is delayed or not possible:
- Restrict iSCSI traffic to known, trusted initiator IP addresses using network access controls.
- Monitor iSCSI traffic for unusual packet sizes or connection patterns that could indicate exploitation attempts.
Which Assets and Systems Are at Risk?
- Asset Types Affected:
- Windows 10 systems - Version 1607 and Version 1809
- Windows Server systems - Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025
- Exposure Level:
- Network-reachable systems - The vulnerability can be exploited remotely over the network
- Windows iSCSI Target Service - The vulnerability affects this service
How Can You Detect CVE-2026-65791 Exploitation?
Exploitation Signatures:
Look for specially crafted network packets targeting the Windows iSCSI Target Service.
Indicators of Compromise (IOCs/IOAs):
- Unusual iSCSI packet sizes
- Unusual iSCSI connection patterns
Behavioral Indicators:
- Unexpected network activity targeting the Windows iSCSI Target Service
- Network traffic patterns consistent with attempted exploitation
Alerting Strategy:
- Priority: Critical
- Trigger alerts for:
- Unusual iSCSI packet sizes
- Unusual iSCSI connection patterns
- Suspicious network traffic targeting the affected service
Remediation & Response
- Remediation Timeline:
- Immediate: Apply the applicable Microsoft security update
- Within 24 hrs: Verify affected systems have reached the required fixed build
- Ongoing: Monitor iSCSI traffic for unusual packet sizes or connection patterns
- Incident Response Considerations:
- Monitor network traffic targeting the Windows iSCSI Target Service
- Review unusual iSCSI packet sizes or connection patterns for potential exploitation attempts
See How Open XDR Strengthens Enterprise Cyber Defense
-
-
- Unified visibility across your security environment
- Flexible integration with your existing security tools
- Faster detection and response to post-attack breaches
- Practical insights for strengthening your cyber defenses
-
CVSS Breakdown Table
| Metric | Value | Description |
|---|---|---|
| Base Score | 9.8 | Critical severity |
| Attack Vector | Network | Can be exploited remotely over a network |
| Attack Complexity | Low | Exploitation does not require special conditions |
| Privileges Required | None | No authentication or privileges are required |
| User Interaction | None | No user action is required |
| Scope | Unchanged | Impact remains within the vulnerable component |
| Confidentiality Impact | High | Successful exploitation can compromise confidentiality |
| Integrity Impact | High | Successful exploitation can compromise system integrity |
| Availability Impact | High | Successful exploitation can disrupt system availability |
References: