Skip to content
feed: live
>_ 0dayNews
CVE Record
[ CRITICAL ] CVE-2026-62815

Microsoft QUIC Unauthenticated Remote Code Execution

Unauthenticated RCE in Microsoft QUIC. No user interaction required; any Windows service exposing QUIC can be exploited remotely with no prior access.

cat cve-2026-62815.json
Vendor
Microsoft
Product
Windows / Microsoft QUIC
CVSS
9.8
EPSS (exploit probability)
N/A
Status
patched
Published

CVE-2026-62815 is a critical remote code execution vulnerability in Microsoft’s QUIC implementation, the network transport protocol underlying HTTP/3 on Windows. No authentication is required and no user interaction is needed — a network-reachable attacker can trigger code execution on any vulnerable Windows host exposing QUIC services.

CVSS 9.8 reflects the worst-case exploitability profile: unauthenticated, network-accessible, zero user interaction. SANS ISC notes this as one of the standout critical issues in the August 2026 patch cycle.

Affected products: Windows Server and Windows client versions with Microsoft QUIC enabled (HTTP/3 services).

Mitigation: Apply the August 2026 Patch Tuesday cumulative update. If immediate patching is not possible, disabling HTTP/3 / QUIC on exposed services reduces the attack surface until the patch can be applied.

Priority: High — CVSS 9.8, unauthenticated, no user interaction required. Prioritize patching any internet-facing or network-exposed services using QUIC.