CVE-2026-72930: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to execute code locally.
Details
Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72930
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-72930 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Windows Secure Socket
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalCVE-2026-73009: Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attac…nvd · 2026-09-08
- mediumCVE-2026-72931: Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protoc…nvd · 2026-09-08
- highCVE-2026-72930: Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacke…nvd · 2026-09-08
- highCVE-2026-71332: Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacke…nvd · 2026-09-08
- highCVE-2026-71332: Windows Secure Socket Tunneling Protocol (SSTP) Elevation of Privilege Vulnerabilitymsrc · 2026-09-08
- criticalCVE-2026-73009: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerabilitymsrc · 2026-09-08
More from Microsoft Security Response Center
- mediumCVE-2026-18924: HTTP/2 server push UAF2026-09-08
- highCVE-2026-69630: Windows Win32k Elevation of Privilege Vulnerability2026-09-08
- unknownCVE-2026-83616: xmldom: Processing Instruction Target Injection Bypasses requireWellFormed2026-09-08
- unknownCVE-2026-85062: Colord: Slow rejection of oversized malformed color strings2026-09-08
- mediumCVE-2026-80834: crypto: sun8i-ce - Remove crypto_rng interface2026-09-08