BoletimSec•September 10, 2026•🇵🇹Translated from Portuguese

Microsoft Fixes Remote Code Execution Flaw in Windows Remote Desktop Client

Microsoft has patched a remote code execution vulnerability in the Windows Remote Desktop Client that could allow an authenticated attacker to execute arbitrary commands over the network. The flaw is tracked as CVE-2026-69485 and carries a CVSS score of 8.8.

The vulnerability arises from the use of an uninitialized resource within the Remote Desktop Client. Under certain conditions, a specially crafted network request can trigger the issue and enable code execution without requiring any user interaction such as opening a file or clicking a link.

Successful exploitation grants an attacker the ability to access sensitive information, modify files, install additional tools, or disrupt services depending on the privileges available on the compromised system. The attack requires the adversary to already possess a low-privileged account on the target.

Affected platforms include multiple versions of Windows 10 and Windows 11, as well as Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025, including Server Core installations.

Microsoft stated that the vulnerability had not been publicly disclosed before the fix and that no evidence of active exploitation exists. The company assesses the likelihood of future exploitation as low. Patches were distributed in the September security updates, including KB5124008 for Windows 11 24H2 and 25H2 and KB5122871 for Windows Server 2025.

Related articles

Security NEXT•Vulnerabilities & Exploits

Critical Vulnerability CVE-2026-12342 Allows Remote Code Execution in SailPoint IdentityIQ

SailPoint has disclosed a critical vulnerability in its identity management product IdentityIQ that stems from insufficient input validation in the web service API. The flaw, identified as CVE-2026-12342, permits an attacker on an adjacent network to execute arbitrary code on the IdentityIQ server without requiring authentication. The vulnerability received a CVSSv3.1 base score of 9.6 and is rated Critical. SailPoint published a security advisory on September 28, 2026, and has released patches for all supported affected versions. The company also plans to include the fix in future patch levels. The issue affects the processing of content sent to the web service API, where improper validation allows malicious input to trigger code execution.

BoletimSec•Vulnerabilities & Exploits

WatchGuard Patches Critical API Flaws in Access Points Allowing Unauthenticated Command Execution

WatchGuard has released firmware version 3.4.8 to address three vulnerabilities affecting its access points, two of which are rated critical. The most severe issues, CVE-2026-86102 and CVE-2026-101891, both scored 9.3 on the CVSS scale and reside in the internal API management service. These flaws permit unauthenticated attackers with network access to execute arbitrary shell commands or bypass access controls without requiring any credentials or valid sessions. A third vulnerability, CVE-2026-87969 with a CVSS score of 8.6, involves command injection through the command-line diagnostic interface but requires authenticated administrator privileges. All firmware versions from 1.0 through 3.4.7 are impacted. The vulnerabilities were disclosed on September 28 with no evidence of active exploitation or public proof-of-concept code available at the time. A compromised access point could serve as an internal foothold for further network attacks due to its visibility into corporate traffic.

AntiMalware•Vulnerabilities & Exploits

Spectre Variant Returns: Branch Target Reuse Attack Extracts Root Password Hash from Linux Memory

Researchers from VUSec and Scuola Superiore Sant’Anna have disclosed Branch Target Reuse, a new Spectre v2 variant that exploits stale branch predictor entries in modern CPUs. The attack targets JIT compilers that generate and reuse executable code at runtime, allowing speculative execution of instructions from previously freed memory regions. On Intel systems with existing mitigations enabled, the researchers demonstrated extraction of the root password hash from the Linux kernel in minutes. Practical proof-of-concept exploits were developed against the Linux kernel, while PoCs were also prepared for Firefox and tested on GraalVM. The issue affects Intel, AMD, and Arm processors, although exploitation success depends on the specific JIT environment and predictor state. Defenses have already been merged into the Linux kernel and GraalVM, while Mozilla continues work on site isolation. The findings highlight that Spectre-class issues remain relevant as long as processors rely on aggressive speculative execution.

Habr•Vulnerabilities & Exploits

EASM Uncovers Forgotten Perimeter Assets Including 11-Year-Old Servers Invisible to Standard Scanners

EASM solutions continuously discover external attack surfaces by starting from public data such as company names, domains, WHOIS records, Certificate Transparency logs, and internet-wide scanners like Shodan and Censys. Unlike traditional vulnerability scanners that only check assets from a predefined list, EASM maps unknown shadow IT including forgotten test servers, abandoned marketing subdomains, exposed APIs, and cloud buckets left open to the internet. The technology follows the same reconnaissance path used by attackers and has become essential for mature vulnerability management programs after years of being considered exotic. Major vendors including Palo Alto Networks Cortex Xpanse, CyCognito, Qualys, Rapid7, and Tenable now lead the market, while Russian providers such as Positive Technologies PT EASM, BI.ZONE EASM, and CyberOK PenOps have grown rapidly since 2022. Without an established process for prioritization and remediation, EASM implementations risk generating overwhelming alert volumes rather than reducing risk. The approach is now viewed as a core component of Continuous Threat Exposure Management (CTEM) frameworks.