A critical remote code execution vulnerability affecting Windows Secure Socket Tunneling Protocol (SSTP) demands immediate attention from UK SMEs, particularly in light of recent Iran-linked cyberattacks on British energy infrastructure.
CVE-2026-62889 is a Critical RCE vulnerability affecting Windows Secure Socket Tunneling Protocol (SSTP) and has a CVSS score of 8.1.
The timing is significant:
in August 2026, The Telegraph revealed that suspected Iran-linked hackers had shut down a small British power-generating facility for four consecutive days the previous month — the first confirmed successful cyberattack by Iranian-linked actors on UK energy infrastructure.
For Kent SMEs using Windows VPN connections for remote access—and that includes most businesses with remote workers or multiple sites—this vulnerability represents a severe risk that must be addressed this week.
What Is CVE-2026-62889 and Why It Matters to UK SMEs
SSTP is a Microsoft VPN protocol that tunnels Point-to-Point Protocol (PPP) traffic through an SSL/TLS channel; it’s commonly used to provide secure remote access to corporate networks over HTTPS.
The protocol is built into Windows and widely deployed across UK businesses for remote worker access, site-to-site connectivity, and secure connections to on-premises resources.
A double free flaw (CWE-415) could allow an unauthenticated remote attacker to execute arbitrary code over a network.
In practical terms, this means an attacker could potentially take control of your VPN server without needing a username or password—simply by sending specially crafted network traffic.
The vulnerability was addressed as part of Microsoft’s August 2026 Patch Tuesday, which
addresses 421 vulnerabilities, including 62 critical and 357 important-severity vulnerabilities.
This month’s updates include three zero-day vulnerabilities: two publicly disclosed and one exploited in the wild.
The Iran-Linked Energy Attack Context: Why Patching Is Urgent
The revelation of successful cyberattacks on UK critical infrastructure changes the threat calculus for all UK businesses.
According to reporting first published by The Telegraph on 22 August 2026, hackers linked to Iran forced a small-scale British power-generating facility offline for four consecutive days in July 2026.
Energy has been the UK’s most targeted sector for cyberattacks for several years running, and every business that depends on electricity, gas, or a supplier’s billing systems has a stake in how resilient that infrastructure really is.
More importantly, the techniques used against critical infrastructure—including exploitation of remote access vulnerabilities—are routinely deployed against SMEs.
According to the National Cyber Security Centre (NCSC), AI will likely continue to “make elements of cyber intrusion operations more effective and efficient, leading to an increase in frequency and intensity of cyber threats.”
The combination of nation-state attack techniques, AI-powered vulnerability discovery, and critical remote access flaws creates a perfect storm for UK businesses.
Microsoft’s New Three-Day Patching Recommendation
Microsoft has fundamentally changed its patching guidance in response to AI-accelerated threat discovery.
Microsoft updated its recommendations for deploying Windows updates to less than three days as the deferral period for quality updates, setting deadlines for those updates to zero or one day, and the update grace period to a maximum of two days.
This represents a major shift from previous best-practice guidance and reflects the reality that
attackers using AI can find and exploit known security gaps within a couple of weeks after security fixes have been issued.
For vulnerabilities like CVE-2026-62889 that affect remote access infrastructure, the exploitation timeline may be even shorter.
As we detailed in our recent article on Microsoft’s three-day deployment recommendation, UK SMEs can no longer afford to delay critical security patches.
Which UK SME Systems Are Affected
CVE-2026-62889 affects organisations using Windows SSTP for remote access, including:
- Windows Server 2016, 2019, 2022, and 2025 running Routing and Remote Access Service (RRAS) with SSTP enabled
- Windows 10 and Windows 11 systems configured as SSTP VPN servers (less common but possible in smaller deployments)
- Azure Virtual Network Gateway configurations using SSTP
- Third-party VPN solutions that rely on Windows SSTP components
Even if your organisation primarily uses other VPN protocols like IPsec or OpenVPN, SSTP may be enabled by default on Windows servers. The vulnerability can be exploited if the service is running, regardless of whether it’s your primary remote access method.
What Kent SMEs Must Do This Week
1. Deploy August 2026 Security Updates Immediately
The fix for CVE-2026-62889 is included in the August 2026 cumulative updates. For Windows 11,
this update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates.
This is particularly relevant for businesses also managing the June 2026 UEFI Secure Boot certificate expiry.
Priority systems for patching:
- All Windows servers running RRAS or VPN services (highest priority)
- Domain controllers and other critical infrastructure servers
- Windows 10 and Windows 11 workstations with remote access enabled
- Azure Virtual Machines running Windows Server roles
2. Audit Your Remote Access Configuration
Many UK SMEs don’t have complete visibility into which remote access protocols are enabled on their infrastructure. Use this vulnerability as a catalyst to audit:
- Which VPN protocols are enabled on your servers (SSTP, L2TP, PPTP, IKEv2)
- Whether SSTP is enabled but not actually used (unnecessary attack surface)
- Which accounts have remote access permissions
- Whether multi-factor authentication is enforced for all remote connections
3. Review Patch Management Processes Against the New Three-Day Standard
If your organisation is still deploying critical security updates on a monthly cycle—typically 1-2 weeks after Patch Tuesday—you’re now operating outside Microsoft’s recommended security posture. As discussed in our article on AI-powered vulnerability discovery, the volume of patches continues to increase while the safe deployment window shrinks.
4. Consider SSTP Alternatives for Long-Term Security
While patching CVE-2026-62889 is essential, consider whether SSTP remains the best remote access solution for your organisation. Modern alternatives include:
- Azure VPN Gateway with IKEv2 (better performance and security)
- Windows Always On VPN with modern authentication
- Zero Trust Network Access (ZTNA) solutions that eliminate traditional VPN architecture
- Microsoft Entra application proxy for specific application access
The Broader Pattern: Critical Infrastructure and SME Security Converge
The UK Government’s 2025/2026 Cyber Security Breaches Survey found that 43% of businesses experienced a cyber security breach or attack during the previous 12 months.
For medium-sized businesses,
the figure increased to 65% for medium-sized businesses and 69% for large businesses.
The Iran-linked energy infrastructure attack demonstrates that sophisticated threat actors are actively targeting UK systems. While your Kent SME may not operate critical national infrastructure, the same vulnerabilities—particularly in remote access systems—are being exploited across all sectors.
Ransomware groups now target SMEs because they are less likely to have strong incident response capabilities.
Related security concerns for UK SMEs include the recent critical Exchange Server vulnerabilities and the ongoing risk from business email compromise attacks that often begin by exploiting remote access vulnerabilities.
Verify Your Patch Status and Get Expert Support
CVE-2026-62889 represents a critical risk to UK SMEs using Windows remote access infrastructure. The combination of a high-severity vulnerability score (CVSS 8.1), unauthenticated remote exploitation, and confirmed nation-state attacks on UK infrastructure means this patch cannot be deferred.
If you’re uncertain whether your systems are vulnerable, unable to deploy patches within Microsoft’s three-day window, or need help auditing your remote access security posture, Meridian Micro Limited can help. Our team provides comprehensive patch management, security auditing, and infrastructure support for Kent and South East businesses.
Call us on 01303 883111 to schedule an urgent security review or to discuss bringing your patch management processes in line with Microsoft’s updated recommendations. Don’t wait for a breach to discover your VPN infrastructure is vulnerable—act this week while patches are still ahead of active exploitation.
