VDB

CVE-2026-73025

CVE-2026-73025 PUBLISHED CVSS 9.8 CRITICAL

Reported by microsoft · Published September 8, 2026

Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.

Risk Scores

CVSS 3.1
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Affected Products

VendorProductVersions
MicrosoftWindows 10 Version 160710.0.14393.0
MicrosoftWindows 10 Version 180910.0.17763.0
MicrosoftWindows Server 20126.2.9200.0
MicrosoftWindows Server 2012 (Server Core installation)6.2.9200.0
MicrosoftWindows Server 2012 R26.3.9600.0
MicrosoftWindows Server 2012 R2 (Server Core installation)6.3.9600.0
MicrosoftWindows Server 201610.0.14393.0
MicrosoftWindows Server 2016 (Server Core installation)10.0.14393.0
MicrosoftWindows Server 201910.0.17763.0
MicrosoftWindows Server 2019 (Server Core installation)10.0.17763.0
MicrosoftWindows Server 202210.0.20348.0
MicrosoftWindows Server 202510.0.26100.0
MicrosoftWindows Server 2025 (Server Core installation)10.0.26100.0
MicrosoftWindows Server 202210.0.20348.0
microsoftwindows_server_201910.0.17763.0, 10.0.17763.0
MicrosoftWindows 10 Version 160710.0.14393.0
MicrosoftWindows Server 2012 R2 (Server Core installation)6.3.9600.0
MicrosoftWindows Server 2019 (Server Core installation)10.0.17763.0
microsoftwindows_10_160710.0.14393.0
microsoftwindows_server_202210.0.20348.0

…and 14 more

Timeline

  • Sep 8, 2026 Coalition ESS Score
  • Sep 8, 2026 CVE Published
  • Sep 9, 2026 Security Advisory
  • Sep 9, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›