Threat Intelligence / CVE / CVE-2026-23666

CVE-2026-23666

CVSS 9.8 (CRITICAL) · EPSS 0.2% · Priority 6.3/10 · Published 2026-04-14

As of 2026-05-07, CVE-2026-23666 is a CVSS 9.8 (CRITICAL-severity) vulnerability. EPSS exploitation probability 0.2%. Threadlinqs Intelligence tracks 2 threats exploiting it.

Last updated: 2026-05-07

Windows TCP/IP IPv6 remote code execution vulnerability caused by an integer overflow in IPv6 fragment reassembly. Reachable from any adjacent network and rated wormable by Microsoft MSRC, allowing unauthenticated attackers to achieve code execution via crafted IPv6 packets.

CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C

Weaknesses (CWE)

CWE-190

Threats tracking this CVE

References

Full detection coverage & IOCs for threats exploiting CVE-2026-23666 are available via the Threadlinqs MCP server (Purple tier). View plans →

← all vulnerabilities · Markdown version · Threadlinqs Intelligence

Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.