Skip to content

CVE-2026-69730

Windows DNS Server use-after-free lets unauthenticated attackers execute code remotely (CVE-2026-69730)

Critical 9.8 Vendor: Microsoft Published

Use-after-free in Windows DNS Server (CVE-2026-69730) allows network-based code execution without privileges or user interaction. Microsoft has released fixes for affected Windows 10 and Windows Server builds; apply the September 2026 update.

What happened

CVE-2026-69730 is a use-after-free vulnerability (CWE-416) in the Windows DNS Server component. An attacker who can reach an affected DNS server over the network can exploit it without credentials, with low attack complexity and without any user action. Microsoft describes the outcome as code execution over a network. The CVSS v3.1 score is 9.8 Critical, with a network attack vector, no privileges required, no user interaction, unchanged scope and high impact on confidentiality, integrity and availability. Microsoft also rates this vulnerability as Critical. The sources used for this advisory record no known exploitation and no public disclosure. There is no CISA KEV entry for this CVE.

Who is affected

Microsoft lists the following products as affected, before the corresponding fixed builds listed below: Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022 and Windows Server 2025, including Server Core installations, plus Windows 10 Version 1607 and Windows 10 Version 1809.

What to do now

  1. Apply the Microsoft security update for your version. The fixed builds are: Windows Server 2012: 6.2.9200.26349 (KB5123065); Windows Server 2012 R2: 6.3.9600.23398 (KB5123066); Windows Server 2016 and Windows 10 Version 1607: 10.0.14393.9512 (KB5123099); Windows Server 2019 and Windows 10 Version 1809: 10.0.17763.9245 (KB5122876); Windows Server 2022: 10.0.20348.5622 (KB5122882); Windows Server 2025: 10.0.26100.33438 (KB5122871). Server Core installations use the same build numbers as their full installations. 2. Microsoft has not listed any workarounds for this vulnerability, so a patch should be the primary remediation. 3. Where patching must be scheduled, reduce exposure of the DNS Server service to untrusted networks while the update is pending. 4. After patching, verify that the relevant fixed build is installed and that DNS servers are reachable only as intended.

How to detect it

Microsoft has not published indicators of compromise for CVE-2026-69730. Start with an inventory of systems running the Windows DNS Server role and identify which are reachable from untrusted networks, since the vulnerability requires network access. That exposure review is the main responsible detection step available here.

Beyond the patch

DNS is core infrastructure, and a critical, network-reachable flaw there is an exposure problem as much as a patch problem. Virtual CISO Services (vCISO) can help keep internet-facing DNS servers inside an exposure-management routine, and Managed Detection & Response (MDR) can monitor for the code-execution and privilege activity that would follow a successful exploit. Apply the update first; then make sure the next exposed service is found before an advisory exists.

Affected and fixed versions

ProductAffectedFixed in
Windows 10 Version 160710.0.14393.0 – < 10.0.14393.951210.0.14393.9512
Windows 10 Version 180910.0.17763.0 – < 10.0.17763.924510.0.17763.9245
Windows Server 20126.2.9200.0 – < 6.2.9200.263496.2.9200.26349
(Server Core installation) 6.2.9200.26349
R2 6.3.9600.23398
R2 (Server Core installation) 6.3.9600.23398
Windows Server 2012 (Server Core installation)6.2.9200.0 – < 6.2.9200.263496.2.9200.26349
Windows Server 2012 R26.3.9600.0 – < 6.3.9600.233986.3.9600.23398
(Server Core installation) 6.3.9600.23398
Windows Server 2012 R2 (Server Core installation)6.3.9600.0 – < 6.3.9600.233986.3.9600.23398
Windows Server 201610.0.14393.0 – < 10.0.14393.951210.0.14393.9512
(Server Core installation) 10.0.14393.9512
Windows Server 2016 (Server Core installation)10.0.14393.0 – < 10.0.14393.951210.0.14393.9512
Windows Server 201910.0.17763.0 – < 10.0.17763.924510.0.17763.9245
(Server Core installation) 10.0.17763.9245
Windows Server 2019 (Server Core installation)10.0.17763.0 – < 10.0.17763.924510.0.17763.9245
Windows Server 202210.0.20348.0 – < 10.0.20348.562210.0.20348.5622
Windows Server 202510.0.26100.0 – < 10.0.26100.3343810.0.26100.33438
(Server Core installation) 10.0.26100.33438

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.