Skip to content
Multiple CVEs Affect Windows RRAS with Remote Code Execution Vulnerabilities

Multiple CVEs Affect Windows RRAS with Remote Code Execution Vulnerabilities

First seen 10 Mar 2026, 17:28 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 16, 2026 at 23:51 UTC

Three critical vulnerabilities have been identified in the Windows Routing and Remote Access Service (RRAS), allowing both unauthorized and authorized attackers to execute code over a network. CVE-2026-25172 and CVE-2026-26111 enable unauthorized access, while CVE-2026-25173 permits authorized attackers to exploit the same weakness. All three vulnerabilities were published on March 10, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 206d ago How this analysis works

Timeline

2026-03-10
CVE-2026-25172 published
2026-03-10
CVE-2026-25173 published
2026-03-10
CVE-2026-26111 published

More articles in this cluster (14)

Following this threat?

Track CVE-2026-25172 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed