CVE-2026-69860: Windows Imaging Component Remote Code Execution Vulnerability
Published Sep 8, 2026
·Updated
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
Other sources
Windows Imaging Component Remote Code Execution Vulnerability
— Microsoft
Affected Software
1 affected component
Microsoft Windows Imaging Component
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
CVE Published
via MITRE·05:12 PM
Data Sourced
via MITRE·05:12 PM
DescriptionSeverity
Data Sourced
via NVD·06:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker does not need prior privileges, and the attack vector is network-based. Exploitation does require user interaction.
2
What is the potential impact if exploitation succeeds?
Successful exploitation can allow remote code execution. The published severity vector indicates high impact to confidentiality, integrity, and availability.
3
Is exploitation known to be occurring?
The available data marks exploit code maturity as unproven (E:U). It does not state that exploitation has been observed in the wild.