CVE-2026-73009 hits the Windows SSTP service and needs no password
Future Technology
New article published
SECURITY
CVE-2026-73009 hits the Windows SSTP service and needs no password
CVE-2026-73009 is a CVSS 9.8 RCE flaw in the Windows SSTP service that needs no password. If your server terminates VPN traffic, check this one first.
Key Takeaways
- CVE-2026-73009 is a use-after-free RCE in the Windows SSTP service rated CVSS 9.8
- Exploitation needs no authentication, just a crafted packet to an exposed SSTP listener
- SSTP is usually published straight to the internet on TCP 443 by Windows Server RRAS
- Microsoft fixed 973 vulnerabilities this month, two of them already under active exploitation
You received this because you subscribe to Future Technology.