CVE-2026-62815Patch(microsoft / windows_11_23h2)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch microsoft windows_11_23h2 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.

2.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_11_23h2
  • windows_11_24h2
  • windows_11_25h2
  • windows_11_26h1

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 14 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 10 signals
  • Technical details provided in 13 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 2 mentions (2026-08-13); latest day: 2
  • 14 total mentions across 9 days

Affected systems

Vendors
Products
windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2022windows_server_2025

Deep dive

Activity timeline14 mentions / 9d
01122Mentions · 2026-08-11: 1Mentions · 2026-08-12: 1Mentions · 2026-08-13: 2Mentions · 2026-08-17: 2Mentions · 2026-08-18: 1Mentions · 2026-08-19: 2Mentions · 2026-08-20: 1Mentions · 2026-08-21: 2Mentions · 2026-08-26: 2PoC Mentioned / Linked · 2026-08-19: 1PoC Mentioned / Linked · 2026-08-21: 1Patch / Workaround · 2026-08-11: 1Patch / Workaround · 2026-08-12: 1Patch / Workaround · 2026-08-13: 1Patch / Workaround · 2026-08-17: 1Patch / Workaround · 2026-08-19: 1Patch / Workaround · 2026-08-20: 1Patch / Workaround · 2026-08-21: 2Patch / Workaround · 2026-08-26: 2Technical Details · 2026-08-11: 1Technical Details · 2026-08-12: 1Technical Details · 2026-08-13: 2Technical Details · 2026-08-17: 2Technical Details · 2026-08-19: 2Technical Details · 2026-08-20: 1Technical Details · 2026-08-21: 2Technical Details · 2026-08-26: 208-1108-1208-1308-1708-1808-1908-2008-2108-26
Signal classification3 categories
Patch
857.1%
Disclosure
428.6%
General
214.3%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-08-111
Patch1
2026-08-121
Patch1
2026-08-132
Disclosure2
2026-08-172
General1Patch1
2026-08-181
General1
2026-08-192
Disclosure1Patch1
2026-08-201
Patch1
2026-08-212
Disclosure1Patch1
2026-08-262
Patch2
Full discourse14 posts
  • Omair 🇵🇸@w3bd3vil
    Patch

    Microsoft's QUIC had a UAF (CVE-2026-62815), which can cause a BSoD on IIS with http/3 configured or SMB over QUIC. PoC included. Both non-default, but internet-exposed assets are more than I expected. Read more https://krashconsulting.com/blog/cve-2026-62815-quickly-patch/ https://t.co/d3spK3NnSL

    Post summary

    Microsoft’s QUIC has a use‑after‑free CVE (CVE‑2026‑62815) that can crash IIS and SMB services; a PoC is available and a patch is recommended.

    030109707
    7.2K followersView on X
  • TheSAS2026@TheSAScon
    Patch

    🔥 This month's Patch Thursday featured a fix for CVE-2026-62815 (CVSS 9.8) - a dangerous RCE vulnerability exploiting the QUIC protocol, reported by Yuki Chen (@guhe120). That is a useful hint about the level of technical depth behind the #TheSAS2026 program committee and the expected talk quality. Yuki is part of the committee this year, and if you want to be in the room for serious conversations on vulnerability discovery, reporting, and what today's bug hunting landscape looks like, SAS is the place. Early bird pricing ends in just a few days: 👉 https://thesascon.com/

    Post summary

    The message announces a patch for CVE‑2026‑62815, highlighting it as a severe RCE affecting QUIC with a CVSS of 9.8, and promotes the SAS2026 conference.

    00060590
    4.1K followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    Microsoft 2026年8月更新、Windows QUICにCVSS 9.8の認証不要RCE https://www.cybernote.click/2026/08/12/microsoft-quic-cve-2026-62815-rce-2/ #IT #Security #cybersecurity

    Post summary

    Microsoft disclosed a high‑severity (CVSS 9.8), unauthenticated remote code execution vulnerability in Windows QUIC in August 2026, with a reference link for further details.

    0001051
    209 followersView on X
  • Human Firewall@HumanFirewallHQ
    Disclosure

    The 9.8s: CVE-2026-62878 — Windows DNS Server, stack-based buffer overflow, no interaction, WORMABLE. ZDI's advice: test fast, patch internet-facing DNS first. CVE-2026-62815 — Microsoft QUIC, RCE, no auth, no user interaction. Internet-facing = tonight's work.

    Post summary

    The post discloses two new CVEs, details their technical nature, and recommends patching, with no mention of exploits or active attacks.

    1000060
    2 followersView on X
  • VulniPulse@vulnipulse
    Patch

    🚨 CRITICAL CVE ALERT CVE-2026-62815 · Microsoft Windows Server 2022 · CVSS 9.8 Attackers could execute arbitrary code. Upgrade to a vendor-listed fixed release. 🔎 Full advisory: https://vulnipulse.com/advisories/microsoft-cve-2026-62815 #CyberSecurity #CVE #Microsoft #WindowsServer

    Post summary

    A critical Windows Server 2022 vulnerability (CVE‑2026‑62815) with CVSS 9.8 allows arbitrary code execution; users are urged to upgrade to the vendor‑provided patch.

    1000046
    7 followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Patch

    A critical RCE (CVE-2026-62815) in Microsoft QUIC demands immediate attention. This zero-day allows unauthenticated remote code execution, severely impacting data privacy & integrity in transit. Patch urgently! #Cybersecurity #NetworkSecurity #ZeroDay

    Post summary

    CVE-2026-62815 is an unauthenticated remote code execution vulnerability in Microsoft QUIC; users are urged to apply a patch immediately.

    0000069
    17 followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Disclosure

    New zero-days emerge: Critical QUIC RCE (CVE-2026-62815, Aug '26) allows unauthenticated code execution, severely impacting data privacy & integrity in transit. Patch Windows & related services immediately. #Cybersecurity #Anonymous #News

    Post summary

    The post announces the discovery of a critical QUIC RCE vulnerability (CVE-2026-62815) and urges immediate patching of Windows and related services.

    0000031
    17 followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Patch

    New critical RCEs in MS QUIC (CVE-2026-62815) & Windows DNS (CVE-2026-62878) demand urgent patching to protect data. Also, MLflow SSRF (CVE-2026-64849) exposes internal services. Act now! #Cybersecurity #Vulnerabilities #NetSec

    Post summary

    The post highlights critical RCEs in MS QUIC and Windows DNS and an SSRF in MLflow, urging immediate patching to protect data and internal services.

    0000078
    17 followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Patch

    New critical RCEs: MS QUIC (CVE-2026-62815), Kemp LoadMaster (CVE-2026-8037), S2OPC (Aug 18), & Win DNS (CVE-2026-62878) threaten data privacy/integrity in transit. Patch NOW! #Cybersecurity #Vulnerabilities #InfoSec

    Post summary

    The post highlights several newly disclosed critical RCEs and urges immediate patching, but does not provide exploit code or evidence of active exploitation.

    0000060
    17 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【緊急】CVE-2026-62815 マイクロソフトのMicrosoft Windows 11 23h2に深刻な脆弱性|即時対応が必要 https://www.cybernote.click/2026/08/17/cve-2026-62815-microsoft-windows-11-23h2/ #IT #Security #cybersecurity

    Post summary

    The post announces a severe vulnerability (CVE‑2026‑62815) in Windows 11 23h2 but provides no technical details, PoC, exploit code, or patch information.

    0000055
    210 followersView on X
  • DailyCVE@dailycve
    General

    🔴 #Microsoft QUIC, Remote Code Execution, #CVE-2026-62815 (Critical) -DC-Aug2026-1510 https://dailycve.com/microsoft-quic-remote-code-execution-cve-2026-62815-critical-dc-aug2026-1510/

    Post summary

    The tweet links to a news article announcing a critical Remote Code Execution vulnerability in Microsoft QUIC (CVE-2026-62815). No PoC, exploit, active use, patch info, or debunking claim is present.

    0000030
    228 followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Patch

    Aug 2026 Patch Tuesday critical RCEs: Microsoft QUIC (CVE-2026-62815) & Windows DNS Server (CVE-2026-62878). These flaws severely impact data privacy & integrity in transit. Immediate patching is vital. #Cybersecurity #InfoSec #Vulnerability

    Post summary

    Patch Tuesday announces critical RCE vulnerabilities in Microsoft QUIC (CVE-2026-62815) and Windows DNS Server (CVE-2026-62878); users should apply the latest patches immediately to safeguard data privacy and integrity.

    0000062
    17 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    Microsoft 2026年8月更新、Windows QUICにCVSS 9.8の認証不要RCE https://www.cybernote.click/2026/08/12/microsoft-quic-cve-2026-62815-rce/ #IT #Security #cybersecurity

    Post summary

    The post announces a high‑severity (CVSS 9.8) authentication‑less RCE in Windows QUIC, but provides no PoC, exploit details, or patch information.

    0000054
    212 followersView on X
  • Windows Forum@windowsforum
    Patch

    🚨 Microsoft QUIC has a remote-code execution flaw, and the public details are basically a locked filing cabinet. If your systems accept QUIC traffic, patch first and investigate later. https://windowsforum.com/security-alerts.84/cve-2026-62815-patch-microsoft-quic-remote-code-execution.442636/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #RemoteCodeExecution #MicrosoftQuic #August2026Updates #Cve202662815 https://t.co/XP2zHF9I6Y

    Post summary

    The post announces CVE-2026-62815, a remote‑code execution flaw in Microsoft QUIC, and urges users to apply the available patch.

    0000048
    1.3K followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2025---

Explore more