SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-73009

CRITICAL · CVSS 9.8 EPSS 0.91%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in the Windows Secure Socket Tunneling Protocol (SSTP) allows unauthorized attackers to execute arbitrary code remotely, posing a significant risk to system integrity and confidentiality. Organizations utilizing Windows systems, particularly those relying on SSTP for secure communications, should prioritize patching this critical vulnerability to mitigate potential exploitation. Immediate action is essential to protect sensitive data and maintain network security.

CVE
CVE-2026-73009
Severity
CRITICAL
CVSS
9.8
EPSS
0.91%
Windows

Original NVD Description

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.