Vulnerability
Published 2026-09-15
Verified 2026-09-19

Microsoft Windows Shell RCE (CVE-2026-69829); CVSS 9.8 — WASOC 20260915001

WA Cyber Security Unit advisory 20260915001 (15 September 2026, TLP:CLEAR) highlights CVE-2026-69829, a Critical remote code execution flaw in Microsoft Windows Shell with CVSS 9.8. WASOC states successful exploitation could allow an unauthenticated attacker to execute arbitrary code and potentially fully compromise affected systems. Affected products/versions are as listed by Microsoft on the MSRC update-guide entry for CVE-2026-69829 (JS-rendered; versions not mirrored here beyond vendor listing). WASOC reports no exploitation observed on Western Australian Government networks at time of writing and recommends applying Microsoft’s fixes per normal patch timeframes. Primary: Microsoft MSRC CVE-2026-69829; AU wire: WASOC 20260915001.

Product
Microsoft Windows Shell
Versions
Vendor-listed products and versions on MSRC CVE-2026-69829 (WASOC points administrators there)
CVSS
9.8
Exploited in Australia?
no
Patch to
Apply Microsoft security updates for CVE-2026-69829 per MSRC; prioritise internet-facing and high-value Windows endpoints/servers

Primary: Microsoft MSRC — CVE-2026-69829 (Windows Shell RCE) · Vendor: Microsoft Security Update Guide · CVE: CVE-2026-69829 · WASOC 20260915001 — Windows Shell RCE (15 Sep 2026)

vulnerabilities australia