Windows iSCSI Weak Authentication Vulnerability in Microsoft Products
CVE-2026-73025
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-73025?
The Windows iSCSI implementation contains a vulnerability that enables unauthorized attackers to bypass its authentication mechanisms over a network. This flaw can allow malicious actors to exploit the iSCSI service, potentially leading to unauthorized access and exposure of sensitive data. The issue emphasizes the importance of robust security protocols in network storage solutions to prevent exploitability. It is essential for users and administrators to stay informed about this vulnerability and apply necessary patches to safeguard their systems against such attacks.
Affected Version(s)
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9512
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.9245
Windows Server 2012 (Server Core installation) x64-based Systems 6.2.9200.0 < 6.2.9200.26349