CVE-2026-69266
massInteger Overflow RCE in Microsoft Windows DHCP Server
CVE-2026-69266 is an integer overflow or wraparound flaw (CWE-190) in the Windows DHCP Server service, assigned by Microsoft. An unauthorized attacker who can reach the service over the network can send crafted traffic that triggers faulty integer arithmetic, resulting in remote code execution in the context of the DHCP Server service. The published CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:R) rates it 8.8 (high), indicating a low-complexity network attack requiring no special privileges, with a user-interaction element noted in the recorded vector. Organizations running the DHCP Server role on the listed Windows 10 and Windows Server releases are affected, and because DHCP servers are reachable by every device on the networks they serve, internal network exposure is typically broad. There are no known reports of in-the-wild exploitation, no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS currently estimates only a 0.4% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update addressing CVE-2026-69266 to all affected Windows 10 and Windows Server hosts through the regular monthly update channel, prioritizing internet-exposed or multi-tenant DHCP servers. To scope patching, inventory whether the DHCP Server role is installed (e.g., 'Get-WindowsFeature DHCP' on Windows Server); as an interim mitigation, restrict which network segments and VLANs can reach the DHCP service (UDP ports 67/68).
| microsoft Windows 10 | 1607 |
| microsoft Windows 10 | 1809 |
| microsoft Windows Server | 2012 |
| microsoft Windows Server | 2016 |
| microsoft Windows Server | 2019 |
| microsoft Windows Server | 2022 |
| microsoft Windows Server | 2025 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Integer overflow or wraparound in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.