Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-62815: Microsoft QUIC allows unauthorized code execution over networks

CVE-2026-62815 · published 25 days ago
Summary

Microsoft's QUIC protocol is affected, which can be exploited by attackers to run malicious code on vulnerable systems. This could lead to unauthorized access and data theft. Microsoft will likely release a patch to fix this issue, and users should update their systems as soon as possible.

What to do
  • Update microsoft windows 11 version 23h2 to version 10.0.22631.7517 or later.
  • Update microsoft windows 11 version 24h2 to version 10.0.26100.9168 or later.
  • Update microsoft windows 11 version 25h2 to version 10.0.26200.9168 or later.
  • Update microsoft windows 11 version 26h1 to version 10.0.28000.2704 or later.
  • Update microsoft windows server 2022 to version 10.0.20348.5499 or later.
  • Update microsoft windows server 2025 to version 10.0.26100.33296 or later.
  • Update microsoft windows server 2025 (server core installation) to version 10.0.26100.33296 or later.
Affected software
VendorProductAffected versions
microsoft windows 11 version 23h2 < 10.0.22631.7517
microsoft windows 11 version 24h2 < 10.0.26100.9168
microsoft windows 11 version 25h2 < 10.0.26200.9168
microsoft windows 11 version 26h1 < 10.0.28000.2704
microsoft windows server 2022 < 10.0.20348.5499
microsoft windows server 2025 < 10.0.26100.33296
microsoft windows server 2025 (server core installation) < 10.0.26100.33296
Original advisory text
Microsoft QUIC Remote Code Execution Vulnerability
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
Severity
9.8 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-416Use After Free
Timeline
Published11 Aug 2026
Updated3 Sep 2026
First seen11 Aug 2026
Sources
CVE-2026-62815 · MITRE
Monitor software like this
Free during beta