VDB
CVE-2026-26111
CVE-2026-26111
PUBLISHED
CVSS 8 HIGH
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
EPSS 0.09% · 25.6th percentile
Risk Scores
CVSS 3.1
8
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
0.09%
25.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| microsoft | windows_11_23H2 | 10.0.22631.0, 10.0.22631.0 |
| Microsoft | Windows 11 Version 23H2 | 10.0.22631.0 |
| microsoft | windows_server_2022 | 10.0.20348.0, 0 |
| Microsoft | Windows Server 2012 R2 | 6.3.9600.0 |
| Microsoft | Windows Server 2012 (Server Core installation) | 6.2.9200.0 |
| microsoft | windows_10_21H2 | 10.0.19044.0 |
| microsoft | windows_11_25H2 | 10.0.26200.0 |
| microsoft | windows_server_2016 | 0, 10.0.14393.0, 10.0.14393.0 |
| microsoft | windows_10_1809 | 10.0.17763.0 |
| Microsoft | Windows Server 2016 | 10.0.14393.0 |
| microsoft | windows_server_2012_R2 | 6.3.9600.0, 6.3.9600.0 |
| microsoft | windows_11_24H2 | 10.0.26100.0 |
| Microsoft | Windows Server 2019 (Server Core installation) | 10.0.17763.0 |
| microsoft | windows_10_22H2 | 10.0.19045.0 |
| microsoft | windows_server_23h2 | 10.0.25398.0 |
| Microsoft | Windows Server 2025 | 10.0.26100.0 |
| microsoft | windows_10_1607 | 10.0.14393.0 |
| Microsoft | Windows 10 Version 1607 | 10.0.14393.0 |
| Microsoft | Windows 10 Version 22H2 | 10.0.19045.0 |
| microsoft | windows_server_2019 | 10.0.17763.0, 10.0.17763.0, 0 |
…and 16 more
Exploit Intelligence
- https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1 (msrc)
- CIRCL seen: CVE-2026-26111 (circl-sighting)
- CIRCL seen: CVE-2026-26111 (circl-sighting)
- CIRCL seen: CVE-2026-26111 (circl-sighting)
- CIRCL seen: CVE-2026-26111 (circl-sighting)
- CIRCL seen: CVE-2026-26111 (circl-sighting)
- CIRCL seen: CVE-2026-26111 (circl-sighting)
- Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability (circl)
- Windows RRAS Remote Code Execution Vulnerability (CVE-2026-26111) - SE-RCE Exploit (cxsecurity)
- cvrf.go (github-poc)
…and 13 more exploits
Timeline
- Mar 10, 2026 CVE Published
- Mar 10, 2026 PoC Published
- Mar 10, 2026 PoC Published
- Mar 10, 2026 PoC Published
- Mar 11, 2026 EPSS Score
- Mar 11, 2026 PoC Published
- Mar 11, 2026 PoC Published
- Mar 11, 2026 Security Advisory
- Mar 12, 2026 EPSS Score
- Mar 13, 2026 EPSS Score
- Mar 14, 2026 EPSS Score
- Mar 15, 2026 EPSS Score
References
- Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-26111 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24283 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24288 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25166 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23660 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24293 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23671 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25177 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25186 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26132 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25190 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25185 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25172 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23667 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24287 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23674 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26127 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23669 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25170 advisory
…and 32 more