Перейти к содержанию

Around 90,000 servers in Russia may be vulnerable due to a critical error in Windows RDS

The vulnerability can be exploited without logging in

A critical vulnerability, CVE-2026-69525, with a CVSS 3.1 score of 9.8, has been discovered in Windows Remote Desktop Services (RDS). Exploiting this vulnerability allows an attacker to gain full control over the affected system.

Image generated by Grok AI Image source: Grok Imagine

Network access to RDS is sufficient for the attack; no user credentials or actions are required. Microsoft also rates the likelihood of exploitation as high. The issue affects several versions of Windows Server, including 2012, 2016, 2019, 2022, and 2025, as well as some editions of Windows 10 and Windows 11.

According to BI.ZONE EASM, approximately 90,000 systems with active remote access services have been identified in the Russian segment of the internet. In the event of an attack, malicious actors could install malware, modify system settings, and gain access to data.

Microsoft released patches on September 8, 2026. Organizations are advised to install the latest updates and check their external perimeter. Until patches are installed, RDP access should be restricted to trusted sources, and services should not be left exposed on the internet unnecessarily.