CVE-2026-69620
massUnauthenticated Stack Buffer Overflow in Windows DHCP Server
CVE-2026-69620 is a stack-based buffer overflow (CWE-121) in the DHCP Server component of Windows. An unauthorized attacker who can send traffic to the DHCP service over a network can trigger the overflow with crafted requests; the CVSS high attack-complexity score (AC:H) indicates the trigger is not trivially reliable. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability on the affected host. Exposure is effectively limited to machines running the DHCP Server role on Windows 10 1607/1809 (LTSC) and Windows Server 2012, 2016, 2019, 2022, and 2025, which are typically domain-joined or enterprise servers. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.7% probability of exploitation within 30 days, so no confirmed in-the-wild exploitation is known.
What to do: Apply Microsoft's security update for CVE-2026-69620 as soon as it is available, prioritizing Windows Servers where the DHCP Server role is installed (check with Get-WindowsFeature DHCP on Server, or the DHCP Server service on the host). As interim mitigation, restrict network access to the DHCP service (UDP 67/68) to trusted management or client segments. Note that Windows Server 2012 is past mainstream support, so organizations still running it should confirm extended-security-update coverage and patch it as well.
| microsoft Windows 10 | 1607 |
| microsoft Windows 10 | 1809 |
| microsoft Windows Server | 2012 |
| microsoft Windows Server | 2016 |
| microsoft Windows Server | 2019 |
| microsoft Windows Server | 2022 |
| microsoft Windows Server | 2025 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.