ZeroHour

CVE-2026-69546

mass

Use-After-Free RCE in Microsoft Active Directory Domain Services

CVSS 3.1
8.1 high
EPSS
<1%p52
Published
()
Modified
AI analysis

CVE-2026-69546 is a use-after-free (CWE-416) memory corruption flaw in Microsoft's Active Directory Domain Services (AD DS), the directory service role that runs on Windows Server domain controllers. It can be triggered over the network by an unauthenticated attacker, although the high attack-complexity metric suggests exploitation requires favorable timing or conditions rather than a simple, repeatable request. Successful exploitation yields remote code execution on the domain controller with the confidentiality, integrity, and availability of the host all rated high, which in practice risks compromise of the identity infrastructure that underpins the entire domain. Any organization running the AD DS role on Windows Server is affected; the exact server builds are enumerated in Microsoft's September 2026 security updates. As of now there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns it roughly a 0.7% chance of exploitation within 30 days.

What to do: Apply the September 2026 Windows Server security updates to all domain controllers as a priority, since AD DS hosts are high-value targets even when the flaw is not yet exploited in the wild. Until patching, restrict network reachability of domain controllers to trusted management and authentication traffic and monitor for anomalous DC traffic. Note the high attack complexity means opportunistic exploitation is less likely, but treat the patch as urgent given domain-controller compromise cascades to the whole domain.

Affected
Microsoft Active Directory Domain Services (AD DS) on Windows Server
Estimated exposure
mass≈1M+ domain controllers worldwide (AD DS is the default directory for most Windows Server estates) — Active Directory is deployed by the overwhelming majority of Windows-using enterprises and government networks, with millions of domain controllers in operation per public surveys and Microsoft's own market-share statements, so the install…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Microsoft's September 2026 Patch Tuesday fixes a record 966 flaws, including two Windows zero-days actively exploited to gain SYSTEM privileges.

Microsoft's September 2026 Patch Tuesday addresses a record 966 vulnerabilities, including 105 rated Critical, 81 of them remote code execution bugs. Two zero-days were actively exploited: a Windows Update Stack link-following flaw and a Windows ALPC heap-based buffer overflow, both allowing local elevation to SYSTEM privileges. The ALPC flaw was reported by Volexity and Proofpoint researchers, while the Update Stack flaw was credited to Romain Deperne and the Microsoft Threat Intelligence Centre. Microsoft shared no details on how the flaws were exploited in attacks.

BleepingComputer · 7d agoAdvisory in the wildCVE-2026-69805CVE-2026-58649CVE-2026-69806+27 CVEs1