Scantide
Live local intelligence
2026-10-04 11:08 CEST · Intelligence refreshed (Europe/Stockholm)

Understand software risk,
with the evidence visible.

Search software, operating systems, packages, CVEs, KBs, campaigns, advisories, named operations or GHSAs and review correlated vulnerability, campaign, advisory, exploitation, update, affected-product and lifecycle intelligence in one place.

Latest synchronized CVE
CVSS 6.5 Published 2026-09-30 14:45 CEST
Vendor
Affected products
1 affected products/devices 1 software
General vulnerability query Recent High & critical CVEs

Query the vulnerability time window. Default 7 days; narrow to the last 24 hours or expand to 14 or 30 days when needed.

34intelligence collections available
0related products displayed
12evidence categories matched
23unique affected products/devices
Correlated intelligenceChecked
NVD applicability intelligenceRelevant evidence found
ENISA EUVD intelligenceRelevant evidence found
Zero Day Initiative advisory intelligenceChecked
Zero Day Initiative upcoming disclosuresAvailable
Credential risk intelligenceAvailable
Public exploit evidenceChecked
Known exploitationChecked
Exploit probabilityRelevant evidence found
Security advisory intelligenceRelevant evidence found
GitHub AdvisoriesRelevant evidence found
OSV vulnerability intelligenceAvailable
Wordfence WordPress vulnerability intelligenceAvailable
Scantide WordPress correlation intelligenceAvailable
Lifecycle intelligenceAvailable
Weakness intelligenceRelevant evidence found
Collaborative vulnerability OSINTRelevant evidence found
FBI / IC3 real-world campaign intelligenceAvailable
CERT-EU advisory and threat intelligenceAvailable
Europol / EC3 operational cybercrime intelligenceAvailable
JVN / Japan vulnerability advisory intelligenceAvailable
Singapore CSA / SingCERT advisory intelligenceRelevant evidence found
Taiwan TWCERT/CC vulnerability intelligenceAvailable
South Korea KISA / KrCERT vulnerability intelligenceRelevant evidence found
Microsoft security update correlationRelevant evidence found

CVSS 9.8/10 Critical severity

CVE lookup — correlated security and lifecycle intelligence

Vendor
Affected products
,
,
,
,
+18 more
Direct connected intelligence KBs, campaigns & Oracle
Connected intelligence Direct relationships for
Matched intelligence coverage 12 sources
SingCERT KISA / KrCERT Microsoft KB EUVD Vulnrichment GHSA EPSS CIRCL CWE CVE Nvd Applicability Affected Products

Windows iSCSI Target Service Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.

Intelligence snapshot

The fastest view of exploitation, corroboration and affected asset classes. Full evidence remains available below.

12 correlated intelligence sources
No confirmed exploitation flag Based on currently correlated Scantide feeds
12 sources Independent intelligence collections correlated to this CVE
41 affected Deduplicated products, devices, operating systems and software relationships
0 hardware · 38 OS 3 software/application relationships
2 related advisories No reliable named campaign/operation extracted
16 downstream Across 1 vendor / product ecosystems
Affected operating systems
Microsoft Windows 10 Version 1607Microsoft Windows Server 2019 (Server Core installation)microsoft Windows Server 2022microsoft windows server 2025Microsoft Windows Server 2025 (Server Core installation)Microsoft Windows 10 Version 1809 +32 more
Supply-chain / downstream exposure Products linked downstream through explicit relationship evidence or vendor/product-status advisories. Generic campaign/IOC mentions are excluded from this supply-chain count.
View all downstream evidence
16 downstream products 1 vendors/ecosystems 16 vendor/advisory-supported 16 OS/platform
Microsoft · 16
Campaign / advisory relationships 2 advisories

Named campaigns are shown separately from generic advisory records. Both are direct contextual relationships because the source explicitly contains this CVE; neither implies every affected product shown elsewhere was used in the campaign.

Related advisories / campaign intelligence records

August 2026 Monthly Patch | Cyber Security Agency of Singapore Skip to main content A Singapore Government Agency Web… CSA / SingCERT · AL-2026-103
MS 8월 보안 위협에 따른 정기 보안 업데이트 권고 KISA / KrCERT · KRCERT-7650FA6822EFA73B3D684DC3

Environment impact assessment

41unique affected products/devices
38operating systems
3software / applications
How can this affect my environment?

This is an exposure-oriented interpretation of the intelligence, not a claim that any asset in your environment is vulnerable. Confirm against your own inventory, versions, configurations and embedded components.

  • Operating-system relationships are represented in the affected-product evidence.
  • Software/application relationships are represented, including downstream products that may bundle the vulnerable component.
  • Check the affected-product inventory below against CMDB, software inventory, appliance/device inventory and dependency manifests.
  • For products that bundle the vulnerable component, validate the vendor's own advisory and fixed release rather than assuming the component version alone proves exposure.
  • Prioritize internet-facing, remotely reachable, unauthenticated, known-exploited and business-critical assets first when those signals are present.
Supply-chain / downstream affected products 16 downstream

This view separates downstream/bundled/advisory-derived exposure from direct product assertions. It is correlation evidence, not proof that every listed deployment is exploitable; vendor/version/configuration validation still applies.

16downstream products
1vendors / ecosystems
16OS/platform relationships

Representative downstream relationships

Microsoft Windows Server 2019 (Server Core installation) Operating systems and platforms · Product-associated assertion · NVD/CVE catalog · supporting vendor/advisory evidence
Microsoft Windows Server 2022 Operating systems and platforms · Product-associated assertion · NVD/CVE catalog · supporting vendor/advisory evidence
Microsoft Windows Server 2025 Operating systems and platforms · Product-associated assertion · NVD/CVE catalog · supporting vendor/advisory evidence
Microsoft Windows Server 2025 (Server Core installation) Operating systems and platforms · Product-associated assertion · NVD/CVE catalog · supporting vendor/advisory evidence
Microsoft Windows Server 2012 Operating systems and platforms · Product-associated assertion · NVD/CVE catalog · supporting vendor/advisory evidence
Microsoft Windows Server 2012 (Server Core installation) Operating systems and platforms · Product-associated assertion · NVD/CVE catalog · supporting vendor/advisory evidence
Microsoft Windows Server 2012 R2 Operating systems and platforms · Product-associated assertion · NVD/CVE catalog · supporting vendor/advisory evidence
Microsoft Windows Server 2012 R2 (Server Core installation) Operating systems and platforms · Product-associated assertion · NVD/CVE catalog · supporting vendor/advisory evidence
Microsoft Windows Server 2016 Operating systems and platforms · Product-associated assertion · NVD/CVE catalog · supporting vendor/advisory evidence
Microsoft Windows Server 2016 (Server Core installation) Operating systems and platforms · Product-associated assertion · NVD/CVE catalog · supporting vendor/advisory evidence
Microsoft Windows Server 2019 Operating systems and platforms · Product-associated assertion · NVD/CVE catalog · supporting vendor/advisory evidence
Microsoft Windows Server 2022 (Server Core installation) Operating systems and platforms · Product-associated assertion · Microsoft Kb · supporting vendor/advisory evidence

Complete downstream evidence

Every downstream product relationship Scantide currently correlates for this CVE is listed below. Expand a category to inspect all products and their provenance.

Operating systems and platforms · 16 relationships
Microsoft Windows 10 Version 1607 for 32-bit Systems Microsoft
Vendor/advisory-supported Product-associated Assertion Source: Microsoft Kb medium-high confidence
Microsoft Windows 10 Version 1607 for x64-based Systems Microsoft
Vendor/advisory-supported Product-associated Assertion Source: Microsoft Kb medium-high confidence
Microsoft Windows 10 Version 1809 for 32-bit Systems Microsoft
Vendor/advisory-supported Product-associated Assertion Source: Microsoft Kb medium-high confidence
Microsoft Windows 10 Version 1809 for x64-based Systems Microsoft
Vendor/advisory-supported Product-associated Assertion Source: Microsoft Kb medium-high confidence
Microsoft Windows Server 2012 Microsoft
Vendor/advisory-supported Product-associated Assertion Source: NVD/CVE catalog high confidence
Microsoft Windows Server 2012 (Server Core installation) Microsoft
Vendor/advisory-supported Product-associated Assertion Source: NVD/CVE catalog high confidence
Microsoft Windows Server 2012 R2 Microsoft
Vendor/advisory-supported Product-associated Assertion Source: NVD/CVE catalog high confidence
Microsoft Windows Server 2012 R2 (Server Core installation) Microsoft
Vendor/advisory-supported Product-associated Assertion Source: NVD/CVE catalog high confidence
Microsoft Windows Server 2016 Microsoft
Vendor/advisory-supported Product-associated Assertion Source: NVD/CVE catalog high confidence
Microsoft Windows Server 2016 (Server Core installation) Microsoft
Vendor/advisory-supported Product-associated Assertion Source: NVD/CVE catalog high confidence
Microsoft Windows Server 2019 Microsoft
Vendor/advisory-supported Product-associated Assertion Source: NVD/CVE catalog high confidence
Microsoft Windows Server 2019 (Server Core installation) Microsoft
Vendor/advisory-supported Product-associated Assertion Source: NVD/CVE catalog high confidence
Microsoft Windows Server 2022 Microsoft
Vendor/advisory-supported Product-associated Assertion Source: NVD/CVE catalog high confidence
Microsoft Windows Server 2022 (Server Core installation) Microsoft
Vendor/advisory-supported Product-associated Assertion Source: Microsoft Kb medium-high confidence
Microsoft Windows Server 2025 Microsoft
Vendor/advisory-supported Product-associated Assertion Source: NVD/CVE catalog high confidence
Microsoft Windows Server 2025 (Server Core installation) Microsoft
Vendor/advisory-supported Product-associated Assertion Source: NVD/CVE catalog high confidence

Top downstream vendor ecosystems

Cross-source correlations 11 matched lanes

Direct intelligence-source relationships

Direct intelligence-source lanes: every lane below has direct evidence for

in that Scantide intelligence collection. Lanes share the CVE as their join key; their presence together does not imply that one source explicitly referenced another source's record.

Downstream affected vendors 1 vendors

Affected vendor/product relationships

These vendors are derived from affected product/device evidence tied to this CVE. This is intentionally separate from the direct intelligence-source lanes above: a vendor can have affected products without Scantide having a vendor-specific advisory or Microsoft KB record for the CVE.

1 affected vendors represented
Analyzer searches are accepted only from validated browser forms. CVE identifiers and campaign/advisory names also have strict read-only path-form permalinks for sharing.
View:
2026-10-04 11:08 CESTIntelligence refreshed
1unique CVEs queried and enriched
1unique CVEs correlated to this result
1unique advisories correlated
19intelligence collections queried

Affected software, operating systems, hardware and devices 41

Deduplicated across Scantide's structured CVE, NVD applicability, CSAF, vendor advisory, campaign and downstream product evidence. Taxonomy IDs and evidence-only identifiers are excluded from the asset count. Counts represent relationships Scantide can currently prove, not the theoretical maximum downstream ecosystem.

38Operating systems
3Software / applications
NVD/CVE catalog 13CISA Vulnrichment 28Microsoft Kb 16NVD applicability graph 8Circl Osint 1
Operating systems and platforms (38 — click to show all)
Vendor: Microsoft
Operating systems and platforms Affected range: All listed or unspecified versions Product-associated Assertion
Primary: NVD/CVE catalogCorroborated: CISA Vulnrichmenthigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: All listed or unspecified versions Product-associated Assertion
Primary: NVD/CVE catalogCorroborated: CISA VulnrichmentCorroborated: Microsoft Kbhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: All listed or unspecified versions Product-associated Assertion
Primary: NVD/CVE catalogCorroborated: CISA VulnrichmentCorroborated: Microsoft Kbhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: All listed or unspecified versions Product-associated Assertion
Primary: NVD/CVE catalogCorroborated: CISA VulnrichmentCorroborated: Microsoft Kbhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: All listed or unspecified versions Product-associated Assertion
Primary: NVD/CVE catalogCorroborated: CISA VulnrichmentCorroborated: Microsoft Kbhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: All listed or unspecified versions Product-associated Assertion
Primary: NVD/CVE catalogCorroborated: CISA Vulnrichmenthigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: All listed or unspecified versions Product-associated Assertion
Primary: NVD applicability graph — official CPE Match expansionCorroborated: NVD/CVE catalog — official CPE Match expansionCorroborated: CISA Vulnrichment — official CPE Match expansionCorroborated: NVD applicability graphCorroborated: NVD/CVE catalogCorroborated: CISA VulnrichmentCorroborated: Microsoft Kb — official CPE Match expansionCorroborated: Microsoft Kbhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: All listed or unspecified versions Product-associated Assertion
Primary: NVD/CVE catalogCorroborated: CISA VulnrichmentCorroborated: Microsoft Kbhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: All listed or unspecified versions Product-associated Assertion
Primary: NVD/CVE catalogCorroborated: CISA VulnrichmentCorroborated: Microsoft Kbhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: All listed or unspecified versions Product-associated Assertion
Primary: NVD/CVE catalogCorroborated: CISA VulnrichmentCorroborated: Microsoft Kbhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: All listed or unspecified versions Product-associated Assertion
Primary: NVD/CVE catalogCorroborated: CISA VulnrichmentCorroborated: Microsoft Kbhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: All listed or unspecified versions Product-associated Assertion
Primary: NVD/CVE catalogCorroborated: CISA VulnrichmentCorroborated: Microsoft Kbhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: All listed or unspecified versions Product-associated Assertion
Primary: NVD/CVE catalogCorroborated: CISA VulnrichmentCorroborated: Microsoft Kbhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: version 10.0.14393.0 — before 10.0.14393.9418 Product-associated Assertion
Primary: CISA Vulnrichment — structured affected recordhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: version 10.0.17763.0 — before 10.0.17763.9121 Product-associated Assertion
Primary: CISA Vulnrichment — structured affected recordhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: version 6.2.9200.0 — before 6.2.9200.26280 Product-associated Assertion
Primary: CISA Vulnrichment — structured affected recordhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: version 6.2.9200.0 — before 6.2.9200.26280 Product-associated Assertion
Primary: CISA Vulnrichment — structured affected recordhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: version 6.3.9600.0 — before 6.3.9600.23338 Product-associated Assertion
Primary: CISA Vulnrichment — structured affected recordhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: version 6.3.9600.0 — before 6.3.9600.23338 Product-associated Assertion
Primary: CISA Vulnrichment — structured affected recordhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: version 10.0.14393.0 — before 10.0.14393.9418 Product-associated Assertion
Primary: CISA Vulnrichment — structured affected recordhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: version 10.0.14393.0 — before 10.0.14393.9418 Product-associated Assertion
Primary: CISA Vulnrichment — structured affected recordhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: version 10.0.17763.0 — before 10.0.17763.9121 Product-associated Assertion
Primary: CISA Vulnrichment — structured affected recordhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: version 10.0.17763.0 — before 10.0.17763.9121 Product-associated Assertion
Primary: CISA Vulnrichment — structured affected recordhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: version 10.0.20348.0 — before 10.0.20348.5499 Product-associated Assertion
Primary: CISA Vulnrichment — structured affected recordhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: version 10.0.26100.0 — before 10.0.26100.33296 Product-associated Assertion
Primary: CISA Vulnrichment — structured affected recordhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: version 10.0.26100.0 — before 10.0.26100.33296 Product-associated Assertion
Primary: CISA Vulnrichment — structured affected recordhigh confidence
Vendor: Microsoft
Operating systems and platforms Affected range: All listed or unspecified versions Product-associated Assertion
Primary: Microsoft Kbmedium-high confidence
Vendor: Microsoft
Operating systems and platforms Affected range: All listed or unspecified versions Product-associated Assertion
Primary: Microsoft Kbmedium-high confidence
Vendor: Microsoft
Operating systems and platforms Affected range: All listed or unspecified versions Product-associated Assertion
Primary: Microsoft Kbmedium-high confidence
Vendor: Microsoft
Operating systems and platforms Affected range: All listed or unspecified versions Product-associated Assertion
Primary: Microsoft Kbmedium-high confidence
Vendor: Microsoft
Operating systems and platforms Affected range: All listed or unspecified versions Product-associated Assertion
Primary: Microsoft Kbmedium-high confidence
Vendor: microsoft
Operating systems and platforms Affected range: before 10.0.14393.9418 — hardware x64 — platform * Product-associated Assertion
Primary: NVD applicability graph — official CPE Match expansionhigh confidence
Vendor: microsoft
Operating systems and platforms Affected range: before 10.0.14393.9418 — hardware x64 — platform * Product-associated Assertion
Primary: NVD applicability graph — official CPE Match expansionhigh confidence
Vendor: microsoft
Operating systems and platforms Affected range: before 10.0.17763.9115 — hardware x64 — platform * Product-associated Assertion
Primary: NVD applicability graph — official CPE Match expansionhigh confidence
Vendor: microsoft
Operating systems and platforms Affected range: before 10.0.26100.33222 — hardware x64 — platform * Product-associated Assertion
Primary: NVD applicability graph — official CPE Match expansionhigh confidence
Vendor: microsoft
Operating systems and platforms Affected range: before 10.0.17763.9115 — hardware x64 — platform * Product-associated Assertion
Primary: NVD applicability graph — official CPE Match expansionhigh confidence
Vendor: microsoft
Operating systems and platforms Affected range: before 10.0.20348.5440 — hardware x64 — platform * Product-associated Assertion
Primary: NVD applicability graph — official CPE Match expansionhigh confidence
Vendor: microsoft
Operating systems and platforms Affected range: version r2 — hardware x64 — platform * Product-associated Assertion
Primary: NVD applicability graph — official CPE Match expansionhigh confidence
Software (3 — click to show all)
Vendor: Microsoft
Software Affected range: All listed or unspecified versions Product-associated Assertion
Primary: CISA Vulnrichmentmedium-high confidence
Vendor: Not identified in correlated evidence
Software Affected range: All listed or unspecified versions Product-associated Assertion
Primary: CISA Vulnrichmentmedium-high confidence
Vendor: Microsoft
Software Affected range: All listed or unspecified versions Product-associated Assertion
Primary: Circl Osint — explicit device/model relation from advisory textmedium confidence
European vulnerability intelligence: ENISA EUVD cross-reference: EUVD-2026-56738.
Exploit probability: Estimated exploitation probability 0.97% — percentile 60.6%.
Vulnerability summary: Windows iSCSI Target Service Remote Code Execution Vulnerability
CIRCL OSINT observations: 8 CIRCL OSINT references found. Retrieved types: 8 sighting.
GitHub package advisories 1
Microsoft security update correlation 40

Microsoft CVE ↔ KB relationships from MSRC CVRF and Microsoft Support. Multiple rows can exist for one KB when product/build applicability or support-page evidence differs.

KB5120242
Windows Server 2022 (Server Core installation) Restart Yes MSRC CVRF
KB5120229
Windows Server 2022 MSRC CVRF
KB5120385
Windows Server 2012 R2 (Server Core installation) Restart Yes MSRC CVRF
KB5120386
Windows Server 2012 Restart Yes MSRC CVRF
KB5120233
Windows Server 2025 Restart Yes MSRC CVRF
KB5120418
Windows Server 2016 Restart Yes MSRC CVRF
KB5120238
Windows 10 Version 1809 for x64-based Systems MSRC CVRF
KB5120228
Windows Server 2025 (Server Core installation) MSRC CVRF
KB5120418
Windows 10 Version 1607 for 32-bit Systems Restart Yes MSRC CVRF
KB5120386
Windows Server 2012 (Server Core installation) Restart Yes MSRC CVRF
KB5120385
Windows Server 2012 R2 MSRC CVRF
KB5120385
Windows Server 2012 R2 Restart Yes MSRC CVRF
KB5120386
Windows Server 2012 MSRC CVRF
KB5120418
Windows 10 Version 1607 for 32-bit Systems MSRC CVRF
KB5120238
Windows Server 2019 (Server Core installation) MSRC CVRF
KB5120228
Windows Server 2025 Restart Yes MSRC CVRF
KB5120418
Windows 10 Version 1607 for x64-based Systems MSRC CVRF
KB5120228
Windows Server 2025 (Server Core installation) Restart Yes MSRC CVRF
KB5120238
Windows Server 2019 Restart Yes MSRC CVRF
KB5120418
Windows Server 2016 MSRC CVRF
KB5120238
Windows 10 Version 1809 for x64-based Systems Restart Yes MSRC CVRF
KB5120386
Windows Server 2012 (Server Core installation) MSRC CVRF
KB5120233
Windows Server 2025 MSRC CVRF
KB5120418
Windows 10 Version 1607 for x64-based Systems Restart Yes MSRC CVRF
KB5120418
Windows Server 2016 (Server Core installation) Restart Yes MSRC CVRF
KB5120233
Windows Server 2025 (Server Core installation) Restart Yes MSRC CVRF
KB5120418
Windows Server 2016 (Server Core installation) MSRC CVRF
KB5120238
Windows Server 2019 (Server Core installation) Restart Yes MSRC CVRF
KB5120385
Windows Server 2012 R2 (Server Core installation) MSRC CVRF
KB5120233
Windows Server 2025 (Server Core installation) MSRC CVRF
KB5120242
Windows Server 2022 (Server Core installation) MSRC CVRF
KB5120238
Windows Server 2019 MSRC CVRF
KB5120238
Windows 10 Version 1809 for 32-bit Systems MSRC CVRF
KB5120229
Windows Server 2022 (Server Core installation) MSRC CVRF
KB5120238
Windows 10 Version 1809 for 32-bit Systems Restart Yes MSRC CVRF
KB5120229
Windows Server 2022 (Server Core installation) Restart Yes MSRC CVRF
KB5120228
Windows Server 2025 MSRC CVRF
KB5120229
Windows Server 2022 Restart Yes MSRC CVRF
KB5120242
Windows Server 2022 MSRC CVRF
KB5120242
Windows Server 2022 Restart Yes MSRC CVRF
Evidence coverage

Correlated from multiple vulnerability, exploitation, advisory, package and affected-product intelligence collections.

Affected-product scope: The product/device count is the deduplicated set Scantide can prove from its currently ingested structured records and advisory text. It is not a claim that only those products were affected; component vulnerabilities such as Log4Shell can have a much larger downstream ecosystem. Advisory and vendor references are kept clickable so additional downstream exposure can be followed to the authoritative source.
Coverage note: Scantide correlates multiple public and locally indexed intelligence sources, but no dataset or matching process is complete. Results may omit software, dependencies, affected versions or advisories, and related records do not by themselves prove that a specific installation is vulnerable. Confirm important findings against vendor guidance and the installed product and version.