Skip to content

CVE-2026-69845

Windows DHCP Server heap-based buffer overflow allows remote code execution (CVE-2026-69845)

Critical 9.8 Vendor: Microsoft Published

CVE-2026-69845: Critical heap-based buffer overflow in Windows DHCP Server allows unauthenticated remote code execution without user interaction. Affects Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025 and Windows 10 1607/1809. Apply Microsoft's September 2026 security updates.

What happened

Microsoft describes this as a heap-based buffer overflow in Windows DHCP Server. An unauthorised attacker can trigger it over the network without prior authentication and without a user having to do anything, leading to code execution. The CVSS v3.1 score is 9.8, rated Critical by Microsoft, and reflects high impact on confidentiality, integrity and availability from a network-based attack with low complexity and no required privileges or user interaction.

The advisory does not state that exploitation has been observed in the wild and does not state that details have been publicly disclosed.

Who is affected

Affected products are Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025, including Server Core installations for 2012, 2012 R2, 2016, 2019 and 2025, and Windows 10 Version 1607 and Version 1809. Vulnerable builds are: Windows Server 2012 before 6.2.9200.26349; Windows Server 2012 R2 before 6.3.9600.23398; Windows Server 2016 and Windows 10 Version 1607 before 10.0.14393.9512; Windows Server 2019 and Windows 10 Version 1809 before 10.0.17763.9245; Windows Server 2022 before 10.0.20348.5622; Windows Server 2025 before 10.0.26100.33438.

What to do now

  1. Apply the Microsoft security updates in the 2026-Sep bundle. The fixed builds are:
  • Windows Server 2019 and Windows 10 Version 1809: 10.0.17763.9245 (KB5122876)
  • Windows Server 2022: 10.0.20348.5622 (KB5122882)
  • Windows Server 2025: 10.0.26100.33438 (KB5122871)
  • Windows Server 2016 and Windows 10 Version 1607: 10.0.14393.9512 (KB5123099)
  • Windows Server 2012: 6.2.9200.26349 (KB5123065)
  • Windows Server 2012 R2: 6.3.9600.23398 (KB5123066)

Server Core installations are covered by the same builds where listed.

  1. Prioritise DHCP servers that are reachable from untrusted network segments; these are directly exposed to the unauthenticated network attack.
  2. Microsoft has not listed a workaround, so patching is the primary control. Until patches are applied, restrict network access to DHCP services and monitor affected servers for unexpected behaviour.

How to detect it

Microsoft has not provided indicators of compromise for this CVE. Because the flaw is reachable over the network without credentials, begin by identifying any DHCP server in the affected version range that is reachable from beyond the segments that require DHCP, and confirm its patch state.

Beyond the patch

Beyond patching, network-reachable unauthenticated services such as DHCP belong in exposure management, not just patch queues. Our Virtual CISO Services can help identify exposed services and open ports before an advisory arrives, and our Managed Detection & Response service monitors for the code execution, privilege escalation or credential abuse that would follow a successful exploit.

Affected and fixed versions

ProductAffectedFixed in
Windows 10 Version 160710.0.14393.0 – < 10.0.14393.951210.0.14393.9512
Windows 10 Version 180910.0.17763.0 – < 10.0.17763.924510.0.17763.9245
Windows Server 20126.2.9200.0 – < 6.2.9200.263496.2.9200.26349
(Server Core installation) 6.2.9200.26349
R2 6.3.9600.23398
R2 (Server Core installation) 6.3.9600.23398
Windows Server 2012 (Server Core installation)6.2.9200.0 – < 6.2.9200.263496.2.9200.26349
Windows Server 2012 R26.3.9600.0 – < 6.3.9600.233986.3.9600.23398
(Server Core installation) 6.3.9600.23398
Windows Server 2012 R2 (Server Core installation)6.3.9600.0 – < 6.3.9600.233986.3.9600.23398
Windows Server 201610.0.14393.0 – < 10.0.14393.951210.0.14393.9512
(Server Core installation) 10.0.14393.9512
Windows Server 2016 (Server Core installation)10.0.14393.0 – < 10.0.14393.951210.0.14393.9512
Windows Server 201910.0.17763.0 – < 10.0.17763.924510.0.17763.9245
(Server Core installation) 10.0.17763.9245
Windows Server 2019 (Server Core installation)10.0.17763.0 – < 10.0.17763.924510.0.17763.9245
Windows Server 202210.0.20348.0 – < 10.0.20348.562210.0.20348.5622
Windows Server 202510.0.26100.0 – < 10.0.26100.3343810.0.26100.33438
(Server Core installation) 10.0.26100.33438

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.