CVE-2026-26111Patch(microsoft / windows_server_2012)

MEDIUMCVSS 8.0 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch microsoft windows_server_2012 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-190

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_server_2012
  • windows_server_2016
  • windows_server_2019
  • windows_server_2022

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 12 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 10 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 6d ago at 3 mentions (2026-03-10); latest day: 1
  • 12 total mentions across 7 days

Affected systems

Vendors
Products
windows_server_2012windows_server_2016windows_server_2019windows_server_2022windows_server_2025

1 version affected across 5 products

Deep dive

Activity timeline12 mentions / 7d
01223Mentions · 2026-03-10: 3Mentions · 2026-03-14: 2Mentions · 2026-03-15: 1Mentions · 2026-03-16: 3Mentions · 2026-03-17: 1Mentions · 2026-03-20: 1Mentions · 2026-03-23: 1Active Exploitation · 2026-03-14: 1Patch / Workaround · 2026-03-15: 1Patch / Workaround · 2026-03-16: 2Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-10: 2Technical Details · 2026-03-14: 2Technical Details · 2026-03-15: 1Technical Details · 2026-03-16: 3Technical Details · 2026-03-20: 1Technical Details · 2026-03-23: 103-1003-1403-1503-1603-1703-2003-23
Signal classification4 categories
Patch
650.0%
Disclosure
433.3%
General
18.3%
Active Exploitation
18.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-103
Disclosure2General1
2026-03-142
Active Exploitation1Disclosure1
2026-03-151
Patch1
2026-03-163
Disclosure1Patch2
2026-03-171
Patch1
2026-03-201
Patch1
2026-03-231
Patch1
Full discourse12 posts
  • にゃん☆たく/takumi.a@taku888infinity
    Patch

    Microsoft Releases Out-of-Band Patch For Critical RRAS RCE Vulnerabilities in Windows 11 https://cybersecuritynews.com/windows-11-out-of-band-update/ 『(直訳) 対処対象となる3つのCVEは以下のとおりです。 CVE-2026-25172 — RRAS管理ツールにおけるセキュリティ上の欠陥。悪意のあるリモートサーバーがサービス運用を妨害したり、接続されたデバイス上で任意のコードを実行したりすることが可能になる。 CVE-2026-25173 — 同様の攻撃手法を用いた関連するRRASの脆弱性。被害者が攻撃者制御のサーバーに接続した際に、リモートコード実行やサービス拒否状態を引き起こす可能性がある。 CVE-2026-26111 — 上記の脆弱性のリスクを悪化させるRRASのセキュリティ上の追加問題。適切な条件下ではコード実行が可能になる可能性がある。』

    Post summary

    Microsoft issued out‑of‑band patches for three RRAS RCE CVEs in Windows 11, describing their remote code execution and denial‑of‑service impacts, but provides no PoC, exploit, or evidence of in‑the‑wild attacks.

    110111.0K
    11.4K followersView on X
  • bigmacd@bigmacd16684
    Patch

    Microsoft re-released hotpatch KB5084597 for Windows 11 24H2/25H2 & Enterprise LTSC 2024 to fix 3 RRAS RCE flaws (CVE-2026-25172, CVE-2026-25173, and CVE-2026-26111) allowing a domain-authenticated attacker

    Post summary

    Microsoft re-released hotpatch KB5084597 to address three RRAS Remote Code Execution vulnerabilities in Windows 11 24H2/25H2 and Enterprise LTSC 2024; the post contains technical details but no PoC, exploit code, or claim of active exploitation.

    1000088
    3 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Windows RRAS の脆弱性 CVE-2026-25172/25173/26111 が FIX:緊急のホットパッチ提供 https://iototsecnews.jp/2026/03/15/microsoft-releases-out-of-band-patch-for-critical-rras-rce-vulnerabilities-in-windows-11/ Microsoft が、Windows 11 24H2/25H2 を対象とした、緊急の定例外ホットパッチ KB5084597 をリリースしました。今回の修正は、Windows の Routing and Remote Access Service (RRAS) 管理ツールに存在するメモリ管理の不備が原因となる、3 件のリモートコード実行 (RCE) 脆弱性に対処するものです。 RRAS は、企業ネットワークにおいて VPN 接続やルーティングを管理するための重要なコンポーネントです。修正された CVE-2026-25172/CVE-2026-25173/CVE-2026-26111 は、管理者が RRAS ツールを使用して外部サーバに接続する際に発動するものです。 攻撃者が悪意を持って構築した 偽の RRAS サーバに対して、管理者が接続を試みると、サーバからの不正な応答により、管理者のマシン上で任意のコード実行やサービス拒否 (DoS) が発生するというリスクがあります。ご利用のチームは、ご注意ください。 #CVE202625172 #CVE202625173 #CVE202626111 #Microsoft #RRAS #Vulnerability #Windows

    Post summary

    Microsoft released hotpatch KB5084597 to fix three critical RCE vulnerabilities (CVE-2026-25172, CVE-2026-25173, CVE-2026-26111) in RRAS on Windows 11, addressing memory‑management flaws that could lead to remote code execution or denial of service.

    01000186
    484 followersView on X
  • Haseeb Efani@Haseeb_Efani
    Patch

    BleepingComputer says the hotpatch is cumulative and follows March fixes for CVE-2026-25172, CVE-2026-25173, and CVE-2026-26111.

    Post summary

    BleepingComputer reports a cumulative hotpatch covering CVE‑2026‑25172, CVE‑2026‑25173, and CVE‑2026‑26111, following March fixes. No exploitation details or vulnerability specifics are provided.

    1000044
    2 followersView on X
  • 【學】@manabu2111
    Patch

    Microsoftが「KB5084597」を定例外でリリース ~「Hotpatch」でリモートコード実行 - 窓の杜 https://forest.watch.impress.co.jp/docs/news/2093553.html 、本パッチは、Windowsのリモート アクセス サービス(RRAS)管理ツールで発見されたリモートコードの脆弱性(CVE-2026-25172、CVE-2026-25173、CVE-2026-26111)に、(続く)

    Post summary

    Microsoft issued hotpatch KB5084597 to remediate multiple RCE flaws in the Windows RRAS admin tool, as detailed in the article.

    1000093
    2.2K followersView on X
  • VulDB 🛡@vuldb
    General

    There is a new vulnerability with elevated criticality in Microsoft Windows (CVE-2026-26111) https://vuldb.com/?id.350036

    Post summary

    The text notes a new Windows vulnerability (CVE-2026-26111) but offers no further details on exploitation, mitigation, or technical aspects.

    0000158
    2.1K followersView on X
  • Cert-IST@cert_ist
    Patch

    Microsoft publie un hotpatch OOB pour corriger des failles RCE (CVE-2026-25172, CVE-2026-26111, CVE-2026-25173) dans RRAS sur Windows 11 Enterprise. https://tinyurl.com/2bsyh2e9

    Post summary

    Microsoft released an out‑of‑band hotpatch to remediate three RCE CVEs (CVE‑2026‑25172, CVE‑2026‑26111, CVE‑2026‑25173) affecting RRAS on Windows 11 Enterprise.

    0000098
    963 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26111 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. https://www.cve.org/CVERecord?id=CVE-2026-26111

    Post summary

    The CVE-2026-26111 entry describes an integer overflow in Windows RRAS that can enable remote code execution; no PoC, exploit code, active exploitation, or patch information is referenced.

    00000217
    56.7K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting Windows RRAS vulnerabilities (CVE-2026-26111) by tricking domain users into connecting to malicious servers for remote code execution. Post-compromise lateral movement through enterprise networks highlights the value of runtime segmentation to contain breach chains. #ZeroDay #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/microsoft-2026-windows-11-rras-rce-vulnerability

    Post summary

    The report highlights active exploitation of CVE-2026-26111 in the wild, with attackers tricking users into connecting to malicious RRAS servers for remote code execution, and stresses the importance of runtime segmentation for containment.

    0000073
    1.9K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 #Windows RRAS Integer Overflow allows RCE (#CVE-2026-26111) (HIGH) https://dailycve.com/windows-rras-integer-overflow-allows-rce-cve-2026-26111-high/

    Post summary

    The message announces CVE-2026-26111 as an Integer Overflow that allows remote code execution, but provides no PoC, exploit code, active exploitation evidence, or patch details.

    0000046
    168 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-26111 - High Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. https://www.thehackerwire.com/vulnerability/CVE-2026-26111/ https://t.co/tdp0ob6xpq

    Post summary

    The post discloses a high‑severity integer overflow in Windows RRAS that could lead to remote code execution, but it provides no PoC, patch, or evidence of active exploitation.

    0000028
    133 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-26111: HIGH] Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.#cve,CVE-2026-26111,#cybersecurity https://cvefind.com/CVE-2026-26111

    Post summary

    The post announces CVE-2026-26111 as a high‑severity integer overflow in Windows RRAS that permits remote code execution.

    0000042
    601 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_server_2012--x64
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016--x64
OSmicrosoftwindows_server_2019--x64
OSmicrosoftwindows_server_2022--x64
OSmicrosoftwindows_server_2025--x64

Explore more