CVE-2026-65796: Windows iSCSI Target Service Remote Code Execution Vulnerability
Overview
- Severity
- High (CVSS 8.1)
- CVSS Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Remote Code Execution
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Unlikely
- Patch Tuesday
- 2026-Aug
- Released
- 2026-08-11
- Last Updated
- 2026-08-13
- EPSS Score
- 0.71% (percentile: 51.5%)
Description
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
Affected Products (16)
Windows
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
- Windows Server 2025 (Server Core installation)
- Windows Server 2025
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 Version 1607 for x64-based Systems
- Windows Server 2016
- Windows Server 2016 (Server Core installation)
ESU
- Windows Server 2012
- Windows Server 2012 (Server Core installation)
- Windows Server 2012 R2
- Windows Server 2012 R2 (Server Core installation)
Security Updates (8)
Acknowledgments
Linzishan, Anemone and Zhiniang Peng with HUST
Revision History
- 2026-08-11: Information published.
- 2026-08-13: Updated the CVE title, changed the security impact from Denial of Service to Remote Code Execution, changed the severity from Important to Critical, updated the CVSS score from 5.9 to 8.1, and corrected the severity and impact entries in the Security Updates table. These are informational changes only. Customers who have successfully installed the update do not need to take any further action.