Microsoft QUIC Unauthenticated Remote Code Execution
Unauthenticated RCE in Microsoft QUIC. No user interaction required; any Windows service exposing QUIC can be exploited remotely with no prior access.
- Vendor
- Microsoft
- Product
- Windows / Microsoft QUIC
- CVSS
- 9.8
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
CVE-2026-62815 is a critical remote code execution vulnerability in Microsoft’s QUIC implementation, the network transport protocol underlying HTTP/3 on Windows. No authentication is required and no user interaction is needed — a network-reachable attacker can trigger code execution on any vulnerable Windows host exposing QUIC services.
CVSS 9.8 reflects the worst-case exploitability profile: unauthenticated, network-accessible, zero user interaction. SANS ISC notes this as one of the standout critical issues in the August 2026 patch cycle.
Affected products: Windows Server and Windows client versions with Microsoft QUIC enabled (HTTP/3 services).
Mitigation: Apply the August 2026 Patch Tuesday cumulative update. If immediate patching is not possible, disabling HTTP/3 / QUIC on exposed services reduces the attack surface until the patch can be applied.
Priority: High — CVSS 9.8, unauthenticated, no user interaction required. Prioritize patching any internet-facing or network-exposed services using QUIC.
