CVE-2026-72950
Windows Routing and Remote Access Service (RRAS) Remote Code Execution vulnerability
MSRC advisory September 8, 2026
Alert details
- Source feed
- Microsoft MSRC
- CVE ID
- CVE-2026-72950
- Affected products
- Windows Routing and Remote Access Service (RRAS) Remote Code Execution · Microsoft Windows Routing and Remote Access Service (RRAS) Remote Code Execution · Microsoft
What happened
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
What it means for your business
Windows Routing and Remote Access Service (RRAS) Remote Code Execution vulnerability (CVE-2026-72950) was added to Microsoft’s security update guidance. Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine If you need help checking exposure, call (864) 335-9223.
Sources
Related briefs
Windows Routing and Remote Access Service (RRAS) Remote Code Execution vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution vulnerability (CVE-2026-62819) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability (CVE-2026-88097) was added to Microsoft’s security update guidance. <p>Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Out of bounds memory access in V8 in Microsoft Edge vulnerability
Out of bounds memory access in V8 in Microsoft Edge vulnerability (CVE-2026-0899) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Azure Cosmos DB Elevation of Privilege vulnerability
Azure Cosmos DB Elevation of Privilege vulnerability (CVE-2026-87701) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Need help patching?
PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.