The vulnerability’s exact title is Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability. Microsoft describes it as: “Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.”
Why CVE-2026-73009 matters
The issue is classified as CWE-416, a use-after-free weakness. This class of memory-safety flaw occurs when software continues to use memory after it has been released. In the worst case, carefully constructed network input can turn that programming mistake into code execution.
Microsoft’s advisory states that an unauthenticated attacker could send a specially crafted packet to an affected service over the network. If exploitation succeeds, the attacker could execute code on the target system. No authentication or user interaction is required.
The security rating reflects that potentially serious outcome:
- Severity: Critical
- CVSS base score: 9.8
- CVSS temporal score: 8.5
- CVSS vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C - CWE: CWE-416
- Exploitation assessment: Exploitation Less Likely
- Publicly disclosed: No
- Exploited: No
- Customer action required: Yes
That CVSS vector is the attention-getter: network access, low attack complexity, no privileges, and no user interaction. In short, this is not a vulnerability that waits patiently for someone to click a suspicious attachment.
Patch the Windows systems in scope
Microsoft has supplied updates across a notably broad range of Windows client and server releases. The practical goal is straightforward: deploy the applicable KB and verify that systems reach the corresponding fixed build.
Windows 10
| Affected product | Update and fixed build |
|---|---|
| Windows 10 Version 1607 for 32-bit Systems (x86) | For Windows 10 Version 1607 for 32-bit Systems (x86), install KB5123099 to reach fixed build 10.0.14393.9512. |
| Windows 10 Version 1607 for x64-based Systems | For Windows 10 Version 1607 for x64-based Systems, install KB5123099 to reach fixed build 10.0.14393.9512. |
| Windows 10 Version 1809 for 32-bit Systems (x86) | For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5122876 to reach fixed build 10.0.17763.9245. |
| Windows 10 Version 1809 for x64-based Systems | For Windows 10 Version 1809 for x64-based Systems, install KB5122876 to reach fixed build 10.0.17763.9245. |
| Windows 10 Version 21H2 for 32-bit Systems (x86) | For Windows 10 Version 21H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19044.7725. |
| Windows 10 Version 21H2 for ARM64-based Systems | For Windows 10 Version 21H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725. |
| Windows 10 Version 21H2 for x64-based Systems | For Windows 10 Version 21H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725. |
| Windows 10 Version 22H2 for 32-bit Systems (x86) | For Windows 10 Version 22H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19045.7725. |
| Windows 10 Version 22H2 for ARM64-based Systems | For Windows 10 Version 22H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725. |
| Windows 10 Version 22H2 for x64-based Systems | For Windows 10 Version 22H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725. |
Windows 11
| Affected product | Update and fixed build |
|---|---|
| Windows 11 Version 23H2 for ARM64-based Systems | For Windows 11 Version 23H2 for ARM64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582. |
| Windows 11 Version 23H2 for x64-based Systems | For Windows 11 Version 23H2 for x64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582. |
| Windows 11 Version 24H2 for ARM64-based Systems | For Windows 11 Version 24H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445. |
| Windows 11 Version 24H2 for x64-based Systems | For Windows 11 Version 24H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445. |
| Windows 11 Version 25H2 for ARM64-based Systems | For Windows 11 Version 25H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445. |
| Windows 11 Version 25H2 for x64-based Systems | For Windows 11 Version 25H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445. |
| Windows 11 Version 26H1 for ARM64-based Systems | For Windows 11 Version 26H1 for ARM64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954. |
| Windows 11 version 26H1 for x64-based Systems | For Windows 11 version 26H1 for x64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954. |
Windows Server
| Affected product | Update and fixed build |
|---|---|
| Windows Server 2012 (Server Core installation) (x64) | For Windows Server 2012 (Server Core installation) (x64), install KB5123065 to reach fixed build 6.2.9200.26349. |
| Windows Server 2012 (x64) | For Windows Server 2012 (x64), install KB5123065 to reach fixed build 6.2.9200.26349. |
| Windows Server 2012 R2 (Server Core installation) (x64) | For Windows Server 2012 R2 (Server Core installation) (x64), install KB5123066 to reach fixed build 6.3.9600.23398. |
| Windows Server 2012 R2 (x64) | For Windows Server 2012 R2 (x64), install KB5123066 to reach fixed build 6.3.9600.23398. |
| Windows Server 2016 (Server Core installation) (x64) | For Windows Server 2016 (Server Core installation) (x64), install KB5123099 to reach fixed build 10.0.14393.9512. |
| Windows Server 2016 (x64) | For Windows Server 2016 (x64), install KB5123099 to reach fixed build 10.0.14393.9512. |
| Windows Server 2019 (Server Core installation) (x64) | For Windows Server 2019 (Server Core installation) (x64), install KB5122876 to reach fixed build 10.0.17763.9245. |
| Windows Server 2019 (x64) | For Windows Server 2019 (x64), install KB5122876 to reach fixed build 10.0.17763.9245. |
| Windows Server 2022 (Server Core installation) (x64) | For Windows Server 2022 (Server Core installation) (x64), install KB5122882 to reach fixed build 10.0.20348.5622. |
| Windows Server 2022 (x64) | For Windows Server 2022 (x64), install KB5122882 to reach fixed build 10.0.20348.5622. |
| Windows Server 2025 (Server Core installation) (x64) | For Windows Server 2025 (Server Core installation) (x64), install KB5122871 to reach fixed build 10.0.26100.33438. |
| Windows Server 2025 (x64) | For Windows Server 2025 (x64), install KB5122871 to reach fixed build 10.0.26100.33438. |
Administrator checklist
- Identify systems running one of the affected Windows products listed above.
- Match each device’s Windows release and architecture to its required KB.
- Deploy the update through the organization’s normal Windows update-management process.
- Confirm successful installation and validate the fixed build number, rather than treating update approval as proof of remediation.
- Give particular operational attention to systems that expose or rely on SSTP services, since Microsoft’s stated attack path involves a specially crafted network packet.
CVE-2026-73009 is an example of why monthly Windows security maintenance is not merely housekeeping. The remediation is clearly mapped to KB packages and target builds; the job now is making sure the fleet actually arrives there.
References
- Official MSRC or vendor evidence api.msrc.microsoft.com
- Official MSRC or vendor evidence msrc.microsoft.com
- Official MSRC or vendor evidence api.msrc.microsoft.com