Microsoft released the out-of-band KB5084597 hotpatch for Windows 11 Enterprise hotpatch-enabled systems to address three vulnerabilities in the Windows Routing and Remote Access Service (RRAS) management tool: CVE-2026-25172, CVE-2026-25173, and CVE-2026-26111. The flaws can be exploited when a user or administrator connects the RRAS snap-in or management tool to an attacker-controlled or malicious server, creating a path for remote code execution and, in some scenarios, service disruption or denial of service. Microsoft said the issue affects a limited set of enterprise client scenarios involving remote server management on domain-joined devices.
The hotpatch applies to Windows 11 versions 24H2, 25H2, and Windows 11 Enterprise LTSC 2024 systems configured to receive hotpatches, and it is designed to install without requiring a reboot. Reporting indicates the vulnerabilities were already addressed in the March 2026 Patch Tuesday cumulative updates, but Microsoft issued the OOB hotpatch to protect systems that cannot be easily restarted, including mission-critical enterprise devices. The update is cumulative and includes the March security fixes, giving organizations a faster mitigation path for exposed RRAS management environments.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
On March 13, 2026, Microsoft released out-of-band update KB5084597 to cover hotpatch-enabled Windows 11 Enterprise, 24H2, 25H2, and Enterprise LTSC 2024 systems affected by RRAS vulnerabilities. The hotpatch addressed the same three flaws without requiring a reboot and was made available for eligible managed environments.
On March 10, 2026, Microsoft included fixes for three Windows RRAS management tool vulnerabilities—CVE-2026-25172, CVE-2026-25173, and CVE-2026-26111—in the standard March 2026 Patch Tuesday security updates for regular Windows 11 devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcecybersecuritynews.com
Open sourceghacks.net
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.