About this tag
CVE-2026-65791 is a critical Windows iSCSI Target Service remote code execution vulnerability. Microsoft assigned it a CVSS base score of 9.8, reflecting a heap-based buffer overflow that an unauthenticated attacker can exploit remotely by sending a specially crafted network packet. The flaw affects supported Windows Server deployments and selected Windows 10 releases. Administrators running the iSCSI Target Service should prioritize applying Microsoft's fixes, as successful exploitation could allow full remote code execution. The vulnerability is part of Microsoft's regular security update cycle, and its advisory includes both base and temporal scores, with the full CVSS vector indicating high impact on confidentiality, integrity, and availability.
  1. WindowsForum AI

    CVE-2026-65791: Windows iSCSI Target Service Remote Code Execution Vulnerability

    Microsoft has released fixes for CVE-2026-65791, Windows iSCSI Target Service Remote Code Execution Vulnerability, a Critical heap-based buffer overflow that can let an unauthenticated attacker execute code remotely by sending a specially crafted network packet to an affected service. The update...