Database/Control plane, storage & DevOps

Windows iSCSI Target Service (Windows Server 2012 through Windows Server 2025 / Windows 10 1607+): Three heap-based
Impact
Three heap-based buffer overflows allowing an unauthorized attacker to execute code over the network against the Windows iSCSI Target Service, plus a null-dereference denial of service in the same August 2026 batch. Unauthenticated network RCE against the service that owns every exported virtual disk on the box - the attacker gets SYSTEM on the storage server and, with it, read/write to every tenant VHD it serves. Relevant to GPU operators running Windows-based storage nodes or Hyper-V clusters backing GPU VMs, and to the long tail of Server 2012-era boxes still exporting iSCSI for management infrastructure.
Who can reach it
Any host that can reach TCP 3260 on the Windows storage server. No credentials.
What to do
Apply the August 2026 Windows cumulative update on every server running the iSCSI Target Service role and reboot - which drops all iSCSI sessions and any VM or host booting from those LUNs, so drain first. If the role is enabled but unused (a common leftover on general-purpose Windows servers), remove the role instead of patching it; that permanently deletes the exposure. Restrict 3260 to known initiator addresses with Windows Firewall regardless of patch state. Note Server 2012 is out of mainstream support - confirm your ESU covers this batch or plan the migration.
References
Related entries
- Windows Services for NFS: use-after-free in the ONCRPC XDR driver allows unauthenticated remote code executionCVE-2026-69595 · Windows Services for NFS (ONCRPC XDR driver)Critical
- Linux SUNRPC (xdr_buf_to_bvec, nfsd write path): xdr_buf_to_bvec stores a bio_vec before checking the slot is in rangeCVE-2026-72217 · Linux SUNRPC (xdr_buf_to_bvec, nfsd write path)Critical
- Linux VXLAN driver (transmit-path header pulls): `vxlan_xmit()`, `arp_reduce()` and `vxlan_mdb_entry_skb_get()`CVE-2026-74474 · Linux VXLAN driver (transmit-path header pulls)Critical
- Airflow Keycloak provider: credentials of any confidential client in the realm log into AirflowCVE-2026-76187 · Apache Airflow Keycloak provider (unauthenticated token endpoint, client-credentials grant)Critical
- Airflow FAB provider: password reset fails to evict existing sessions, so a stolen cookie keeps workingCVE-2026-82311 · Apache Airflow FAB provider (password reset does not delete database-backed sessions)Critical
- Linux nfsd: async server-side COPY registers a stateid pointing into a reused request bufferCVE-2026-89676 · Linux NFS server (nfsd, s2s_cp_stateids IDR for async COPY)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.