Microsoft QUIC Remote Code Execution Vulnerability: Early Warning
- Severity
- HIGH
- Affected component
- microsoft quic (nuget)
- Patched version
- e0f55b5fdc9fff0b4465976d066ebd22fb7e2b3b
An early warning has been issued for a critical remote code execution vulnerability in Microsoft QUIC. This vulnerability could allow an unauthorized attacker to execute code over a network.
What happened
An early warning has been issued for a critical remote code execution vulnerability in Microsoft QUIC. This vulnerability, tracked as GHSA-92F5-VC22-8J33 and CVE-2026-62815, reportedly allows an unauthorized attacker to execute code over a network. Successful exploitation could allow the attacker to execute code on the target system. The vulnerability was first flagged on September 8, 2026. It is not yet confirmed if this vulnerability has been exploited in the wild.
The affected component is Microsoft QUIC (nuget). The specific version range of affected versions is not yet authoritatively published, but the patched version is e0f55b5fdc9fff0b4465976d066ebd22fb7e2b3b. Users are advised to upgrade to this patched version to mitigate the risk.
What to do about it
- Upgrade to the patched version e0f55b5fdc9fff0b4465976d066ebd22fb7e2b3b of Microsoft QUIC (nuget).
- Monitor the primary sources for updates on the vulnerability and any further patches that may be released.
- Review your systems to identify any instances of Microsoft QUIC (nuget) and ensure they are updated to the patched version.
- Implement network monitoring to detect any unusual activity that may indicate an attempt to exploit this vulnerability.
How 0Day would have caught this
microsoft quic is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
The specific version range of affected versions is not yet authoritatively published. However, if you are using Microsoft QUIC (nuget), it is recommended to upgrade to the patched version e0f55b5fdc9fff0b4465976d066ebd22fb7e2b3b.
What should I do right now?
Upgrade to the patched version e0f55b5fdc9fff0b4465976d066ebd22fb7e2b3b of Microsoft QUIC (nuget) and monitor the primary sources for updates.
Where can I find more information about this vulnerability?
Consult the primary sources: [GHSA-92f5-vc22-8j33] Microsoft QUIC: Remote Code Execution Vulnerability (https://github.com/advisories/GHSA-92f5-vc22-8j33) and [GHSA-92f5-vc22-8j33] Microsoft QUIC: Remote Code Execution Vulnerability (https://github.com/microsoft/msquic/security/advisories/GHSA-92f5-vc22-8j33).