ZeroHour

CVE-2026-69266

mass

Integer Overflow RCE in Microsoft Windows DHCP Server

CVSS 3.1
8.8 high
EPSS
<1%p36
Published
()
Modified
AI analysis

CVE-2026-69266 is an integer overflow or wraparound flaw (CWE-190) in the Windows DHCP Server service, assigned by Microsoft. An unauthorized attacker who can reach the service over the network can send crafted traffic that triggers faulty integer arithmetic, resulting in remote code execution in the context of the DHCP Server service. The published CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:R) rates it 8.8 (high), indicating a low-complexity network attack requiring no special privileges, with a user-interaction element noted in the recorded vector. Organizations running the DHCP Server role on the listed Windows 10 and Windows Server releases are affected, and because DHCP servers are reachable by every device on the networks they serve, internal network exposure is typically broad. There are no known reports of in-the-wild exploitation, no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS currently estimates only a 0.4% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update addressing CVE-2026-69266 to all affected Windows 10 and Windows Server hosts through the regular monthly update channel, prioritizing internet-exposed or multi-tenant DHCP servers. To scope patching, inventory whether the DHCP Server role is installed (e.g., 'Get-WindowsFeature DHCP' on Windows Server); as an interim mitigation, restrict which network segments and VLANs can reach the DHCP service (UDP ports 67/68).

Affected
microsoft Windows 101607
microsoft Windows 101809
microsoft Windows Server2012
microsoft Windows Server2016
microsoft Windows Server2019
microsoft Windows Server2022
microsoft Windows Server2025
Estimated exposure
masslikely on the order of 1M+ Windows Server instances running the DHCP Server role (well over 100k systems) — The combined installed base of Windows Server 2012-2025 is in the tens of millions and DHCP is one of the most commonly deployed Windows Server roles, often colocated on domain controllers, so hundreds of thousands to millions of affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow or wraparound in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.