CVE-2026-72939
Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service over a network.
- Published Sep 8, 2026
- CVSS 6.5 medium
- 1.1% chance of exploitation in the next 30 days (EPSS)
- A fix is available