Insights from the Latest Global Network Security Report

CVE-2026-65791

CVE-2026-65791: Critical Remote Code Execution Flaw in Windows iSCSI Target Service Explained

CVSS Gauge
CVSS Needle

Summary

CVE-2026-65791 is a critical heap-based buffer overflow in the Windows iSCSI Target Service. An unauthenticated attacker can send a specially crafted network packet to an affected service and potentially execute code remotely. The vulnerability has a CVSS score of 9.8, with network-based exploitation requiring no privileges or user interaction.

The vulnerability affects Windows 10 Version 1607 and 1809, and Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025. Microsoft has released security updates with specific fixed builds for the affected products.

Urgent Actions Required

Which Systems Are Vulnerable to CVE-2026-65791?

Technical Overview

How Does the CVE-2026-65791 Exploit Work?

The attack typically follows these steps:

CVE-2026-65791

What Causes CVE-2026-65791?

Vulnerability Root Cause:

CVE-2026-65791 is caused by a heap-based buffer overflow in the Windows iSCSI Target Service. A specially crafted network packet can trigger the flaw, allowing an unauthorized attacker to execute code remotely.

How Can You Mitigate CVE-2026-65791?

If immediate patching is delayed or not possible:

  • Restrict iSCSI traffic to known, trusted initiator IP addresses using network access controls.
  • Monitor iSCSI traffic for unusual packet sizes or connection patterns that could indicate exploitation attempts.

Which Assets and Systems Are at Risk?

How Can You Detect CVE-2026-65791 Exploitation?

Exploitation Signatures:

Look for specially crafted network packets targeting the Windows iSCSI Target Service.

Indicators of Compromise (IOCs/IOAs):

Behavioral Indicators:

Alerting Strategy:

Remediation & Response

See How Open XDR Strengthens Enterprise Cyber Defense

      • Unified visibility across your security environment
      • Flexible integration with your existing security tools
      • Faster detection and response to post-attack breaches
      • Practical insights for strengthening your cyber defenses
Download the Solution Brief

CVSS Breakdown Table

MetricValue Description
Base Score9.8Critical severity
Attack VectorNetworkCan be exploited remotely over a network
Attack ComplexityLowExploitation does not require special conditions
Privileges RequiredNoneNo authentication or privileges are required
User Interaction NoneNo user action is required
Scope Unchanged Impact remains within the vulnerable component
Confidentiality Impact HighSuccessful exploitation can compromise confidentiality
Integrity Impact HighSuccessful exploitation can compromise system integrity
Availability ImpactHighSuccessful exploitation can disrupt system availability

Related Readings

One Platform for All Adversaries

See Fidelis in action. Learn how our fast and scalable platforms provide full visibility, deep insights, and rapid response to help security teams across the World protect, detect, respond, and neutralize advanced cyber adversaries.