CVE-2026-70585: Use-After-Free in Windows NFS Client Stack
A use-after-free (CWE-416) was found in the Windows Services for NFS ONCRPC XDR Driver, with a CVSS base score of 7.0, published on September 8, 2026. An attacker controlling the NFS server can influence parsing in the client kernel and achieve local code execution.
- CVE-2026-70585 is a use-after-free in the Windows Services for NFS ONCRPC XDR Driver
- CVSS base score 7.0, CWE-416, published September 8, 2026
- Exploitation requires an attacker-controlled NFS server
- Apply September 2026 updates or remove the NFS client feature
Read next
Security