Newsletter

CVE-2026-73009 hits the Windows SSTP service and needs no password

Sent · Daily Briefing
Future Technology

New article published

SECURITY

CVE-2026-73009 hits the Windows SSTP service and needs no password

CVE-2026-73009 is a CVSS 9.8 RCE flaw in the Windows SSTP service that needs no password. If your server terminates VPN traffic, check this one first.

Key Takeaways

  • CVE-2026-73009 is a use-after-free RCE in the Windows SSTP service rated CVSS 9.8
  • Exploitation needs no authentication, just a crafted packet to an exposed SSTP listener
  • SSTP is usually published straight to the internet on TCP 443 by Windows Server RRAS
  • Microsoft fixed 973 vulnerabilities this month, two of them already under active exploitation

You received this because you subscribe to Future Technology.

← Back to the archive

Get the briefing

The biggest tech story, explained in 3 minutes. Delivered free every weekday.

Trusted by thousands of readers