CVE-2026-69845
Windows DHCP Server heap-based buffer overflow allows remote code execution (CVE-2026-69845)
CVE-2026-69845: Critical heap-based buffer overflow in Windows DHCP Server allows unauthenticated remote code execution without user interaction. Affects Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025 and Windows 10 1607/1809. Apply Microsoft's September 2026 security updates.
What happened
Microsoft describes this as a heap-based buffer overflow in Windows DHCP Server. An unauthorised attacker can trigger it over the network without prior authentication and without a user having to do anything, leading to code execution. The CVSS v3.1 score is 9.8, rated Critical by Microsoft, and reflects high impact on confidentiality, integrity and availability from a network-based attack with low complexity and no required privileges or user interaction.
The advisory does not state that exploitation has been observed in the wild and does not state that details have been publicly disclosed.
Who is affected
Affected products are Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025, including Server Core installations for 2012, 2012 R2, 2016, 2019 and 2025, and Windows 10 Version 1607 and Version 1809. Vulnerable builds are: Windows Server 2012 before 6.2.9200.26349; Windows Server 2012 R2 before 6.3.9600.23398; Windows Server 2016 and Windows 10 Version 1607 before 10.0.14393.9512; Windows Server 2019 and Windows 10 Version 1809 before 10.0.17763.9245; Windows Server 2022 before 10.0.20348.5622; Windows Server 2025 before 10.0.26100.33438.
What to do now
- Apply the Microsoft security updates in the 2026-Sep bundle. The fixed builds are:
- Windows Server 2019 and Windows 10 Version 1809: 10.0.17763.9245 (KB5122876)
- Windows Server 2022: 10.0.20348.5622 (KB5122882)
- Windows Server 2025: 10.0.26100.33438 (KB5122871)
- Windows Server 2016 and Windows 10 Version 1607: 10.0.14393.9512 (KB5123099)
- Windows Server 2012: 6.2.9200.26349 (KB5123065)
- Windows Server 2012 R2: 6.3.9600.23398 (KB5123066)
Server Core installations are covered by the same builds where listed.
- Prioritise DHCP servers that are reachable from untrusted network segments; these are directly exposed to the unauthenticated network attack.
- Microsoft has not listed a workaround, so patching is the primary control. Until patches are applied, restrict network access to DHCP services and monitor affected servers for unexpected behaviour.
How to detect it
Microsoft has not provided indicators of compromise for this CVE. Because the flaw is reachable over the network without credentials, begin by identifying any DHCP server in the affected version range that is reachable from beyond the segments that require DHCP, and confirm its patch state.
Beyond the patch
Beyond patching, network-reachable unauthenticated services such as DHCP belong in exposure management, not just patch queues. Our Virtual CISO Services can help identify exposed services and open ports before an advisory arrives, and our Managed Detection & Response service monitors for the code execution, privilege escalation or credential abuse that would follow a successful exploit.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Windows 10 Version 1607 | 10.0.14393.0 – < 10.0.14393.9512 | 10.0.14393.9512 |
| Windows 10 Version 1809 | 10.0.17763.0 – < 10.0.17763.9245 | 10.0.17763.9245 |
| Windows Server 2012 | 6.2.9200.0 – < 6.2.9200.26349 | 6.2.9200.26349 (Server Core installation) 6.2.9200.26349 R2 6.3.9600.23398 R2 (Server Core installation) 6.3.9600.23398 |
| Windows Server 2012 (Server Core installation) | 6.2.9200.0 – < 6.2.9200.26349 | 6.2.9200.26349 |
| Windows Server 2012 R2 | 6.3.9600.0 – < 6.3.9600.23398 | 6.3.9600.23398 (Server Core installation) 6.3.9600.23398 |
| Windows Server 2012 R2 (Server Core installation) | 6.3.9600.0 – < 6.3.9600.23398 | 6.3.9600.23398 |
| Windows Server 2016 | 10.0.14393.0 – < 10.0.14393.9512 | 10.0.14393.9512 (Server Core installation) 10.0.14393.9512 |
| Windows Server 2016 (Server Core installation) | 10.0.14393.0 – < 10.0.14393.9512 | 10.0.14393.9512 |
| Windows Server 2019 | 10.0.17763.0 – < 10.0.17763.9245 | 10.0.17763.9245 (Server Core installation) 10.0.17763.9245 |
| Windows Server 2019 (Server Core installation) | 10.0.17763.0 – < 10.0.17763.9245 | 10.0.17763.9245 |
| Windows Server 2022 | 10.0.20348.0 – < 10.0.20348.5622 | 10.0.20348.5622 |
| Windows Server 2025 | 10.0.26100.0 – < 10.0.26100.33438 | 10.0.26100.33438 (Server Core installation) 10.0.26100.33438 |