CVE-2026-70570: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
Details
Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70570
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-70570 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Windows Routing and
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-72959: Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to g…nvd · 2026-09-08
- highCVE-2026-72950: Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to g…nvd · 2026-09-08
- mediumCVE-2026-72939: Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authori…nvd · 2026-09-08
- highCVE-2026-71353: Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker …nvd · 2026-09-08
- highCVE-2026-71351: Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker …nvd · 2026-09-08
- highCVE-2026-70570: Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to g…nvd · 2026-09-08
More from Microsoft Security Response Center
- mediumCVE-2026-18924: HTTP/2 server push UAF2026-09-08
- highCVE-2026-69630: Windows Win32k Elevation of Privilege Vulnerability2026-09-08
- unknownCVE-2026-83616: xmldom: Processing Instruction Target Injection Bypasses requireWellFormed2026-09-08
- unknownCVE-2026-85062: Colord: Slow rejection of oversized malformed color strings2026-09-08
- mediumCVE-2026-80834: crypto: sun8i-ce - Remove crypto_rng interface2026-09-08