Database/Control plane, storage & DevOps

Windows iSCSI Target Service (Windows Server 2012 through Windows Server 2025 / Windows 10 1607+): Three heap-based
Impact
Three heap-based buffer overflows allowing an unauthorized attacker to execute code over the network against the Windows iSCSI Target Service, plus a null-dereference denial of service in the same August 2026 batch. Unauthenticated network RCE against the service that owns every exported virtual disk on the box - the attacker gets SYSTEM on the storage server and, with it, read/write to every tenant VHD it serves. Relevant to GPU operators running Windows-based storage nodes or Hyper-V clusters backing GPU VMs, and to the long tail of Server 2012-era boxes still exporting iSCSI for management infrastructure.
Who can reach it
Any host that can reach TCP 3260 on the Windows storage server. No credentials.
What to do
Apply the August 2026 Windows cumulative update on every server running the iSCSI Target Service role and reboot - which drops all iSCSI sessions and any VM or host booting from those LUNs, so drain first. If the role is enabled but unused (a common leftover on general-purpose Windows servers), remove the role instead of patching it; that permanently deletes the exposure. Restrict 3260 to known initiator addresses with Windows Firewall regardless of patch state. Note Server 2012 is out of mainstream support - confirm your ESU covers this batch or plan the migration.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.