WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home H2OSecCon 2026 Microsoft Advises to Patch Now to Address Critical Remote Code Execution Vulnerability for MS-RPC
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Microsoft Advises to Patch Now to Address Critical Remote Code Execution Vulnerability for MS-RPC

Author: Jennifer Walker

Created: Thursday, April 14, 2022 - 15:27

Categories: Cybersecurity, Security Preparedness

Action Recommended: Members are strongly encouraged to advise their system administrators to address Microsoft security updates for April 2022. This month’s round of patches includes a critical remote code execution (RCE) vulnerability for an extremely important component of the operating system that allows for arbitrary code execution without authentication or user interaction. System administrators are encouraged to review Microsoft’s advisory to address CVE-2022-26809 and apply the recommended mitigations.

Microsoft’s advisory addresses a critical remote code execution vulnerability in Remote Procedure Call Runtime Library (MS-RPC). A remote, unauthenticated attacker could exploit this vulnerability to take control of an affected system. At this time there is no known exploitation, but that could change soon. Sysadmins can find additional analysis and information about this vulnerability from the SANS Internet Storm Center.

Related Resources

Members Only

(TLP:AMBER) DHS Office of Intelligence and Analysis Reports (May 21, 2026)

May 21, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Weekly Vulnerabilities to Prioritize – May 21, 2026

May 21, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:GREEN) PEAR Ransomware Claims U.S. Drinking Water Utility as Victim

May 21, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar