Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

PDQ: 35 Critical 9.8 CVEs Including RCE and ICS Flaws

PDQ
10/07/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Given time, given how many CVs and stuff like that, I pick a few highlights and then I reference them. This one, I just called the 9.8 club because we had 35 CVs that were rated a 9.8 this month and 34 of those 35 were remote code execution. Internet connection sharing, ICS, I didn't think that was still a thing in Windows. Apparently. Wow. Yeah. And a lot of these are sitting on services that are waiting to be talked to like DHCP, DNS, NetLogon, RRS, NFS.

TL;DR

  • A single monthly patch cycle surfaced 35 CVEs rated 9.8, collectively dubbed the '9.8 Club' by the reviewer.
  • 34 of the 35 critical CVEs involve remote code execution, representing an exceptionally dangerous concentration of high-severity flaws.
  • Internet Connection Sharing (ICS) — a Windows service many consider obsolete — was among the affected components, catching the speaker off guard.

Summary

This short clip highlights a striking finding from a monthly vulnerability review: 35 CVEs rated 9.8 out of 10 in a single month, a grouping the speaker dubs the '9.8 Club.' Of those 35, 34 involve remote code execution, making them among the most dangerous vulnerability classes an organization can face. Particularly notable is the inclusion of Internet Connection Sharing (ICS), a Windows service many assumed was deprecated or irrelevant in modern environments. The speaker also flags that many of these critical vulnerabilities reside in foundational network services — DHCP, DNS, NetLogon, RRS, and NFS — services that are passively listening for connections and therefore exposed without any user interaction required. The implication is clear: organizations relying on these common services may be sitting on unpatched, high-severity attack surfaces without realizing it. This clip serves as a concise but urgent alert for patch management and vulnerability prioritization teams.

Chapters

0:00 - Introducing the 9.8 Club
0:10 - 35 CVEs, 34 RCE Flaws
0:19 - ICS and Passive Network Services

Key Quotes

0:10 "I just called the 9.8 club because we had 35 CVs that were rated a 9.8 this month and 34 of those 35 were remote code execution."
0:19 "Internet connection sharing, ICS, I didn't think that was still a thing in Windows."
0:27 "A lot of these are sitting on services that are waiting to be talked to like DHCP, DNS, NetLogon, RRS, NFS."

FAQ

What is the '9.8 Club' referenced in this video?

The '9.8 Club' is a term coined by the speaker to describe the 35 CVEs rated 9.8 (out of 10) on the CVSS scale identified in a single monthly vulnerability review, 34 of which are remote code execution flaws.

Which Windows services are affected by these critical vulnerabilities?

The affected services mentioned include Internet Connection Sharing (ICS), DHCP, DNS, NetLogon, RRS, and NFS — all common Windows network services that passively listen for connections.


Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Vulnerability Management
  • Security Operations
  • Threat Intelligence
  • Best Practices
  • Technical Deep Dive
  • CVE vulnerability ratings
  • Remote code execution
  • Patch management
  • Windows security
  • Internet Connection Sharing
  • Network service vulnerabilities
  • CVSS scoring
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: PDQ: 35 Critical 9.8 CVEs Including RCE and ICS Flaws

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance

                10/13/202601:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 10/13/2026
                      01:00 PM
                      10/13/2026
                      Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance
                      https://www.truthinit.com/index.php/channel/2159/transitioning-from-cjis-to-ferpa-essential-audit-evidence-for-compliance/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      11:00 AM
                      10/27/2026
                      Maximize Security, Value, and Returns on Your Microsoft Investment
                      https://www.truthinit.com/index.php/channel/2178/maximize-security-value-and-returns-on-your-microsoft-investment/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Leveraging CISA’s Zero Trust Maturity Model in an AI-Driven Landscape
                      https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-in-an-ai-driven-landscape/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Aligning Agentic Intent: Understanding Your Agents' Purpose vs. Their Actions
                      https://www.truthinit.com/index.php/channel/2158/aligning-agentic-intent-understanding-your-agents-purpose-vs-their-actions/
                    • 11/05/2026
                      02:00 PM
                      11/05/2026
                      HUMAN Dialogue: Embracing the Rise of the Agentic Consumer in AI
                      https://www.truthinit.com/index.php/channel/2160/human-dialogue-embracing-the-rise-of-the-agentic-consumer-in-ai/
                    • 11/05/2026
                      02:00 PM
                      11/05/2026
                      Reclaim Your Evenings: Leverage Data Intelligence to Minimize Risk and Boost AI Adoption
                      https://www.truthinit.com/index.php/channel/2172/reclaim-your-evenings-leverage-data-intelligence-to-minimize-risk-and-boost-ai-adoption/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version