CVE-2026-69730
Windows DNS Server use-after-free lets unauthenticated attackers execute code remotely (CVE-2026-69730)
Use-after-free in Windows DNS Server (CVE-2026-69730) allows network-based code execution without privileges or user interaction. Microsoft has released fixes for affected Windows 10 and Windows Server builds; apply the September 2026 update.
What happened
CVE-2026-69730 is a use-after-free vulnerability (CWE-416) in the Windows DNS Server component. An attacker who can reach an affected DNS server over the network can exploit it without credentials, with low attack complexity and without any user action. Microsoft describes the outcome as code execution over a network. The CVSS v3.1 score is 9.8 Critical, with a network attack vector, no privileges required, no user interaction, unchanged scope and high impact on confidentiality, integrity and availability. Microsoft also rates this vulnerability as Critical. The sources used for this advisory record no known exploitation and no public disclosure. There is no CISA KEV entry for this CVE.
Who is affected
Microsoft lists the following products as affected, before the corresponding fixed builds listed below: Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022 and Windows Server 2025, including Server Core installations, plus Windows 10 Version 1607 and Windows 10 Version 1809.
What to do now
- Apply the Microsoft security update for your version. The fixed builds are: Windows Server 2012: 6.2.9200.26349 (KB5123065); Windows Server 2012 R2: 6.3.9600.23398 (KB5123066); Windows Server 2016 and Windows 10 Version 1607: 10.0.14393.9512 (KB5123099); Windows Server 2019 and Windows 10 Version 1809: 10.0.17763.9245 (KB5122876); Windows Server 2022: 10.0.20348.5622 (KB5122882); Windows Server 2025: 10.0.26100.33438 (KB5122871). Server Core installations use the same build numbers as their full installations. 2. Microsoft has not listed any workarounds for this vulnerability, so a patch should be the primary remediation. 3. Where patching must be scheduled, reduce exposure of the DNS Server service to untrusted networks while the update is pending. 4. After patching, verify that the relevant fixed build is installed and that DNS servers are reachable only as intended.
How to detect it
Microsoft has not published indicators of compromise for CVE-2026-69730. Start with an inventory of systems running the Windows DNS Server role and identify which are reachable from untrusted networks, since the vulnerability requires network access. That exposure review is the main responsible detection step available here.
Beyond the patch
DNS is core infrastructure, and a critical, network-reachable flaw there is an exposure problem as much as a patch problem. Virtual CISO Services (vCISO) can help keep internet-facing DNS servers inside an exposure-management routine, and Managed Detection & Response (MDR) can monitor for the code-execution and privilege activity that would follow a successful exploit. Apply the update first; then make sure the next exposed service is found before an advisory exists.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Windows 10 Version 1607 | 10.0.14393.0 – < 10.0.14393.9512 | 10.0.14393.9512 |
| Windows 10 Version 1809 | 10.0.17763.0 – < 10.0.17763.9245 | 10.0.17763.9245 |
| Windows Server 2012 | 6.2.9200.0 – < 6.2.9200.26349 | 6.2.9200.26349 (Server Core installation) 6.2.9200.26349 R2 6.3.9600.23398 R2 (Server Core installation) 6.3.9600.23398 |
| Windows Server 2012 (Server Core installation) | 6.2.9200.0 – < 6.2.9200.26349 | 6.2.9200.26349 |
| Windows Server 2012 R2 | 6.3.9600.0 – < 6.3.9600.23398 | 6.3.9600.23398 (Server Core installation) 6.3.9600.23398 |
| Windows Server 2012 R2 (Server Core installation) | 6.3.9600.0 – < 6.3.9600.23398 | 6.3.9600.23398 |
| Windows Server 2016 | 10.0.14393.0 – < 10.0.14393.9512 | 10.0.14393.9512 (Server Core installation) 10.0.14393.9512 |
| Windows Server 2016 (Server Core installation) | 10.0.14393.0 – < 10.0.14393.9512 | 10.0.14393.9512 |
| Windows Server 2019 | 10.0.17763.0 – < 10.0.17763.9245 | 10.0.17763.9245 (Server Core installation) 10.0.17763.9245 |
| Windows Server 2019 (Server Core installation) | 10.0.17763.0 – < 10.0.17763.9245 | 10.0.17763.9245 |
| Windows Server 2022 | 10.0.20348.0 – < 10.0.20348.5622 | 10.0.20348.5622 |
| Windows Server 2025 | 10.0.26100.0 – < 10.0.26100.33438 | 10.0.26100.33438 (Server Core installation) 10.0.26100.33438 |