type: cve ยท created: 2026-08-12 ยท updated: 2026-08-12 ยท tags: [cve, rce, microsoft, quic, unauthenticated, patch-tuesday] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government, finance, healthcare] ยท au_impact: true
CVE-2026-62815 โ Microsoft QUIC RCE
CVE-2026-62815 is an unauthenticated remote code execution (RCE) vulnerability in Microsoft's QUIC stack, rated CVSS 9.8 and shipped in the August 2026 Patch Tuesday release (2026-08-11).
Vulnerability Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-62815 |
| Type | Unauthenticated remote code execution (RCE) |
| Product | Microsoft QUIC |
| Access | Unauthenticated |
| CVSS | 9.8 |
| Exploitation status | Not flagged as actively exploited in the wild in the August 2026 release |
Context
Patched in Microsoft's August 2026 Patch Tuesday (398 CVEs, 62 Critical per ZDI), one of four unauthenticated RCEs at CVSS 9.8 in the release. The digest flags DNS Server and QUIC as platforms NZISM-covered Windows systems run, so the patch is considered urgent for Windows estates.
Related Pages
- Microsoft Patches 398 Flaws Including A Windows Driver Zero Day Under Active Att โ the August 2026 Patch Tuesday release
Sources: raw/digests/Cyber-Digest-2026-08-12