CVE-2026-72979
Windows DHCP Server use-after-free vulnerability allows remote code execution (CVE-2026-72979)
Use-after-free in Windows DHCP Server allows an unauthenticated attacker to execute code over the network. Microsoft rates the flaw critical and has released fixed builds for affected Windows Server and Windows 10 versions. Apply the September 2026 updates promptly.
What happened
Microsoft's Windows DHCP Server contains a use-after-free vulnerability (CWE-416). An unauthorised attacker can exploit it over the network with no credentials and no user interaction. The CVSS 3.1 base score is 9.8: network attack vector, low attack complexity, and high impact to confidentiality, integrity and availability.
Microsoft rates the issue Critical. No current reports of active exploitation or public disclosure are recorded for this CVE. Microsoft has not published a workaround for the vulnerability.
Who is affected
Windows DHCP Server is a role commonly deployed on Windows Server to hand out IP addresses. Microsoft lists the following affected versions, all before the fixed builds shown in the next section:
- Windows 10 Version 1607: 10.0.14393.0 to before 10.0.14393.9512
- Windows 10 Version 1809: 10.0.17763.0 to before 10.0.17763.9245
- Windows Server 2012 and Server Core installation: 6.2.9200.0 to before 6.2.9200.26349
- Windows Server 2012 R2 and Server Core installation: 6.3.9600.0 to before 6.3.9600.23398
- Windows Server 2016 and Server Core installation: 10.0.14393.0 to before 10.0.14393.9512
- Windows Server 2019 and Server Core installation: 10.0.17763.0 to before 10.0.17763.9245
- Windows Server 2022: 10.0.20348.0 to before 10.0.20348.5622
- Windows Server 2025: 10.0.26100.0 to before 10.0.26100.33438
What to do now
- Apply the September 2026 security updates from Microsoft to every affected system, particularly those running the Windows DHCP Server role. The fixed versions are:
- 6.2.9200.26349 (Windows Server 2012 and Server Core installation)
- 6.3.9600.23398 (Windows Server 2012 R2 and Server Core installation)
- 10.0.14393.9512 (Windows 10 Version 1607; Windows Server 2016 and Server Core installation)
- 10.0.17763.9245 (Windows 10 Version 1809; Windows Server 2019 and Server Core installation)
- 10.0.20348.5622 (Windows Server 2022)
- 10.0.26100.33438 (Windows Server 2025 and Server Core installation)
The corresponding update references from Microsoft are KB5123065, KB5123066, KB5123099, KB5122876, KB5122882 and KB5122871.
- Prioritise hosts running the DHCP Server role. Because the flaw requires no credentials or user interaction, any unpatched DHCP server reachable from a network is at risk.
- If you cannot patch immediately, restrict network reachability to affected servers as far as practicable until the update is installed. Microsoft has not published a workaround.
How to detect it
Microsoft has not published indicators of compromise for this issue. The practical check is exposure and patch state: inventory every system with the Windows DHCP Server role, confirm whether it is reachable from untrusted networks, and verify the fixed build numbers above after deployment.
Beyond the patch
This is a flaw where exposure is the whole story: a network-reachable, pre-authentication service on a role that often lingers unnoticed on older servers. After patching, use Virtual CISO Services (vCISO) to find and reduce exposed DHCP and similar services, and keep Managed Detection & Response (MDR) on the estate to catch post-exploitation moves.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Windows 10 Version 1607 | 10.0.14393.0 – < 10.0.14393.9512 | 10.0.14393.9512 |
| Windows 10 Version 1809 | 10.0.17763.0 – < 10.0.17763.9245 | 10.0.17763.9245 |
| Windows Server 2012 | 6.2.9200.0 – < 6.2.9200.26349 | 6.2.9200.26349 (Server Core installation) 6.2.9200.26349 R2 6.3.9600.23398 R2 (Server Core installation) 6.3.9600.23398 |
| Windows Server 2012 (Server Core installation) | 6.2.9200.0 – < 6.2.9200.26349 | 6.2.9200.26349 |
| Windows Server 2012 R2 | 6.3.9600.0 – < 6.3.9600.23398 | 6.3.9600.23398 (Server Core installation) 6.3.9600.23398 |
| Windows Server 2012 R2 (Server Core installation) | 6.3.9600.0 – < 6.3.9600.23398 | 6.3.9600.23398 |
| Windows Server 2016 | 10.0.14393.0 – < 10.0.14393.9512 | 10.0.14393.9512 (Server Core installation) 10.0.14393.9512 |
| Windows Server 2016 (Server Core installation) | 10.0.14393.0 – < 10.0.14393.9512 | 10.0.14393.9512 |
| Windows Server 2019 | 10.0.17763.0 – < 10.0.17763.9245 | 10.0.17763.9245 (Server Core installation) 10.0.17763.9245 |
| Windows Server 2019 (Server Core installation) | 10.0.17763.0 – < 10.0.17763.9245 | 10.0.17763.9245 |
| Windows Server 2022 | 10.0.20348.0 – < 10.0.20348.5622 | 10.0.20348.5622 |
| Windows Server 2025 | 10.0.26100.0 – < 10.0.26100.33438 | 10.0.26100.33438 (Server Core installation) 10.0.26100.33438 |