Record summary

CVE-2026-65681 has a selected CVSS score of 7.5 (high).

Description

Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.

Description source: GitHub Advisory

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 11, 2026 · Source: CVE List

Affected products and versions

9
ProductSourceVersion rangeStatus
CVE List10.0.14393.0 to < 10.0.14393.9418affected
CVE List10.0.17763.0 to < 10.0.17763.9115affected
CVE List10.0.14393.0 to < 10.0.14393.9418affected

Windows Server 2016 (Server Core installation)

Browse Microsoft / Windows Server 2016 (Server Core installation)
CVE List10.0.14393.0 to < 10.0.14393.9418affected
CVE List10.0.17763.0 to < 10.0.17763.9115affected

Windows Server 2019 (Server Core installation)

Browse Microsoft / Windows Server 2019 (Server Core installation)
CVE List10.0.17763.0 to < 10.0.17763.9115affected
CVE List10.0.20348.0 to < 10.0.20348.5499affected
CVE List10.0.26100.0 to < 10.0.26100.33296affected

Windows Server 2025 (Server Core installation)

Browse Microsoft / Windows Server 2025 (Server Core installation)
CVE List10.0.26100.0 to < 10.0.26100.33296affected

References

2