Microsoft QUIC Vulnerability: Critical CVE-2026-62815 Alert
- Severity
- HIGH
- Affected component
- Microsoft.Native.Quic.MsQuic.OpenSSL (nuget)
- Affected versions
- < 2.1.12 or >= 1.8.0, <= 1.8.0 or >= 2.2.0, < 2.2.7 or >= 2.3.0, < 2.3.5 or < 2.2.3 or >= 1.8.0, <= 1.8.0 or >= 2.5.0-ci.532574, < 2.5.7 or < 2.4.18 or >= 1.8.0, <= 1.8.0 or < 2.2.3 or >= 1.8.0, <= 1.8.0
- Patched version
- e0f55b5fdc9fff0b4465976d066ebd22fb7e2b3b
An early warning has been issued for a critical vulnerability in Microsoft QUIC that could allow remote code execution. Users of affected versions of Microsoft.Native.Quic.MsQuic.OpenSSL and Microsoft.Native.Quic.MsQuic.Schannel are urged to assess their exposure.
What happened
A critical vulnerability, tracked as CVE-2026-62815, has been identified in Microsoft QUIC. This use after free vulnerability reportedly allows an unauthorized attacker to execute code over a network. Successful exploitation could enable the attacker to execute code on the target system. The vulnerability affects specific versions of Microsoft.Native.Quic.MsQuic.OpenSSL and Microsoft.Native.Quic.MsQuic.Schannel.
The vulnerability was first flagged on 2026-09-08T20:27:02+00:00. It is currently under investigation and has not been exploited in the wild. The affected components and version ranges are detailed in the threat data. Users are advised to consult the primary sources for the most accurate and up-to-date information.
What to do about it
- Identify if your systems are using affected versions of Microsoft.Native.Quic.MsQuic.OpenSSL or Microsoft.Native.Quic.MsQuic.Schannel.
- Upgrade to the patched version e0f55b5fdc9fff0b4465976d066ebd22fb7e2b3b for both components.
- Monitor the primary sources for updates on the vulnerability and any additional patches that may be released.
- Implement network-level protections to mitigate the risk of remote code execution.
- Conduct a security review of systems using affected components to ensure no unauthorized code execution has occurred.
How 0Day would have caught this
Microsoft.Native.Quic.MsQuic.OpenSSL is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using Microsoft.Native.Quic.MsQuic.OpenSSL or Microsoft.Native.Quic.MsQuic.Schannel in the specified version ranges. Consult the threat data for the exact versions.
What should I do right now?
Immediately assess if your systems are using affected versions. Upgrade to the patched version e0f55b5fdc9fff0b4465976d066ebd22fb7e2b3b and monitor the primary sources for updates.
Is there an official fix available?
Yes, the patched version e0f55b5fdc9fff0b4465976d066ebd22fb7e2b3b is available for both affected components.