Description
Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.
Published: 2026-09-08
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via iSCSI Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

The vulnerability stems from weak authentication mechanisms in Windows iSCSI. An attacker who can communicate with the iSCSI service over a network can circumvent built‑in security controls. This bypass allows the attacker to gain elevated privileges on the target system, potentially leading to full system compromise. The weakness corresponds to CWE-1390, which describes insecure handling of authentication data.

Affected Systems

Affected operating systems include Microsoft Windows 10 version 1607 and 1809, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025. For each of these releases, both standard and Server Core installations are impacted. No specific patch level is indicated in the advisories, so all instances of these OS versions should be considered vulnerable until an update is applied.

Risk and Exploitability

The CVSS score of 9.8 classifies this as a critical vulnerability. While no EPSS value is provided, the lack of listed exploits in the KEV database does not diminish the risk; the weakness can be employed via the network without any local user interaction. The likely attack vector is a remote network connection to the iSCSI target, and the exploitation requires only that the attacker be able to reach the service. Organizations should assess whether iSCSI is in use and, if so, treat this as an available attack vector.

Generated by OpenCVE AI on September 9, 2026 at 01:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the security update released by Microsoft for Windows iSCSI (refer to the MSRC advisory for details).
  • Disable the iSCSI service or remove it from the system if it is not required for business operations.
  • Configure strict authentication on iSCSI targets and enforce network segmentation or firewall rules to restrict access only to trusted hosts.

Generated by OpenCVE AI on September 9, 2026 at 01:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows Server 2012 (server Core Installation)
Microsoft windows Server 2012 R2
Microsoft windows Server 2012 R2 (server Core Installation)
Microsoft windows Server 2016 (server Core Installation)
Microsoft windows Server 2019 (server Core Installation)
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows Server 2012 (server Core Installation)
Microsoft windows Server 2012 R2
Microsoft windows Server 2012 R2 (server Core Installation)
Microsoft windows Server 2016 (server Core Installation)
Microsoft windows Server 2019 (server Core Installation)
Microsoft windows Server 2025 (server Core Installation)

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.
Title Windows iSCSI Security Feature Bypass Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-1390
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows Server 2012 Windows Server 2012 (server Core Installation) Windows Server 2012 R2 Windows Server 2012 R2 Windows Server 2012 R2 (server Core Installation) Windows Server 2016 Windows Server 2016 (server Core Installation) Windows Server 2019 Windows Server 2019 (server Core Installation) Windows Server 2022 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:37:57.036Z

Reserved: 2026-08-10T18:43:43.200Z

Link: CVE-2026-73025

cve-icon Vulnrichment

Updated: 2026-09-09T09:53:53.494Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:32.490

Modified: 2026-09-24T23:18:57.950

Link: CVE-2026-73025

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:51:22Z

Weaknesses