Microsoft has released fixes for CVE-2026-65791, Windows iSCSI Target Service Remote Code Execution Vulnerability, a Critical heap-based buffer overflow that can let an unauthenticated attacker execute code remotely by sending a specially crafted network packet to an affected service. The update matters most to administrators running the Windows iSCSI Target Service across supported Windows Server deployments, but Microsoft’s affected-product record also includes selected Windows 10 releases.

Microsoft’s advisory assigns CVE-2026-65791 a CVSS base score of 9.8 and a temporal score of 8.5. Its full CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C. The weakness is classified as CWE-122, a heap-based buffer overflow.

Microsoft states: “Windows iSCSI Target Service Remote Code Execution Vulnerability: Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.” The company’s exploitation explanation is unusually direct: an unauthenticated attacker could send a specially crafted packet over the network to an affected service, potentially gaining code execution on the target. No authentication or user interaction is required.

Publicly disclosed: No

Exploited: No

Customer action required: Yes

Abstract illustration of connected devices separated by a protected security boundary.A network-reachable service flaw with maximum practical urgency​

The 9.8 base score reflects a combination administrators should treat as an urgent patching signal: network attack vector, low attack complexity, no privileges required, no user interaction, and potential compromise of confidentiality, integrity, and availability. Microsoft’s exploitation assessment is Exploitation Unlikely, but that rating does not remove the need to deploy the update. It describes Microsoft’s assessment at release time; it does not change the fact that a successful attack can result in code execution on a target system.

The immediate operational question is whether systems run the Windows iSCSI Target Service and whether that service is reachable from networks an attacker could access. Microsoft’s advisory identifies the affected service and says exploitation involves a crafted packet sent over the network. That makes patch deployment the remediation Microsoft has supplied, rather than relying on user-awareness measures or an authentication control that the described attack does not require.

The affected list spans Windows Server 2012 through Windows Server 2025, including Server Core installations where listed, as well as Windows 10 Version 1607 and Version 1809. Organizations with older server branches should pay particular attention to the distinct KB and fixed-build targets rather than assuming a single cumulative update package applies everywhere.


KB5120418 covers Windows Server 2016 and Windows 10 Version 1607​

Microsoft maps KB5120418 to fixed build 10.0.14393.9418 for four affected product entries. Administrators should use the product and architecture designation in their inventory to select the applicable deployment target.

  • For Windows 10 Version 1607 for 32-bit Systems (x86), install KB5120418 to reach fixed build 10.0.14393.9418.
  • For Windows 10 Version 1607 for x64-based Systems, install KB5120418 to reach fixed build 10.0.14393.9418.
  • For Windows Server 2016 (Server Core installation) (x64), install KB5120418 to reach fixed build 10.0.14393.9418.
  • For Windows Server 2016 (x64), install KB5120418 to reach fixed build 10.0.14393.9418.

The shared build target is useful for patch-validation work: systems in each of these four product categories must reach 10.0.14393.9418 under Microsoft’s advisory mapping. The common KB does not erase the difference between client, full server, and Server Core inventory classifications, which should remain distinct in deployment reporting.

KB5120238 addresses Windows Server 2019 and Windows 10 Version 1809​

For the Version 1809 and Server 2019 product families, Microsoft identifies KB5120238, with fixed build 10.0.17763.9121. This mapping includes both x86 and x64 Windows 10 entries, plus full and Server Core Windows Server 2019 entries.

  • For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5120238 to reach fixed build 10.0.17763.9121.
  • For Windows 10 Version 1809 for x64-based Systems, install KB5120238 to reach fixed build 10.0.17763.9121.
  • For Windows Server 2019 (Server Core installation) (x64), install KB5120238 to reach fixed build 10.0.17763.9121.
  • For Windows Server 2019 (x64), install KB5120238 to reach fixed build 10.0.17763.9121.

As with the Server 2016 family, the key post-installation check is the fixed build Microsoft specifies rather than the assumption that an update was merely offered or downloaded. For this group, that version is 10.0.17763.9121.

Separate remediation for Windows Server 2012 and Windows Server 2012 R2​

Microsoft lists distinct updates for Windows Server 2012 and Windows Server 2012 R2. Both full and Server Core installations appear in the affected-product data, so patch-management queries should account for both installation types.

  • For Windows Server 2012 (Server Core installation) (x64), install KB5120386 to reach fixed build 6.2.9200.26280.
  • For Windows Server 2012 (x64), install KB5120386 to reach fixed build 6.2.9200.26280.
  • For Windows Server 2012 R2 (Server Core installation) (x64), install KB5120385 to reach fixed build 6.3.9600.23338.
  • For Windows Server 2012 R2 (x64), install KB5120385 to reach fixed build 6.3.9600.23338.

The KB distinction here is material. Windows Server 2012 requires KB5120386 and fixed build 6.2.9200.26280, while Windows Server 2012 R2 requires KB5120385 and fixed build 6.3.9600.23338. Treating the two as interchangeable would leave a deployment validation gap.


Windows Server 2022 and Windows Server 2025 have two listed build paths​

Microsoft’s affected-product record provides two KB-to-build mappings for both Windows Server 2022 and Windows Server 2025, including Server Core and full installations. Administrators should match their servicing deployment with the corresponding fixed build listed by Microsoft.

  • For Windows Server 2022 (Server Core installation) (x64), install KB5120229 to reach fixed build 10.0.20348.5440; install KB5120242 to reach fixed build 10.0.20348.5499.
  • For Windows Server 2022 (x64), install KB5120229 to reach fixed build 10.0.20348.5440; install KB5120242 to reach fixed build 10.0.20348.5499.
  • For Windows Server 2025 (Server Core installation) (x64), install KB5120228 to reach fixed build 10.0.26100.33222; install KB5120233 to reach fixed build 10.0.26100.33296.
  • For Windows Server 2025 (x64), install KB5120228 to reach fixed build 10.0.26100.33222; install KB5120233 to reach fixed build 10.0.26100.33296.

For Windows Server 2022, the relevant pairs are KB5120229 with build 10.0.20348.5440 and KB5120242 with build 10.0.20348.5499. For Windows Server 2025, the pairs are KB5120228 with build 10.0.26100.33222 and KB5120233 with build 10.0.26100.33296.

Deployment should focus on the service and fixed builds​

Microsoft’s published remediation is explicit for every affected product: install the mapped KB and verify the associated fixed build. The advisory does not describe an authentication prerequisite for an attacker, a user-driven trigger, or a user interaction step; administrators should therefore prioritize systems operating the affected iSCSI target functionality and validate remediation through build-level compliance.

CVE-2026-65791 is a Critical, network-based remote code execution issue with a 9.8 base score, and Microsoft requires customer action. The concrete completion criteria are the KB and build mappings above: 10.0.14393.9418, 10.0.17763.9121, 6.2.9200.26280, 6.3.9600.23338, 10.0.20348.5440, 10.0.20348.5499, 10.0.26100.33222, or 10.0.26100.33296, as applicable to the installed Windows product.