CVE-2026-69680
massOrigin Validation Flaw in Windows DNS Enables Network Spoofing
CVE-2026-69680 is an origin validation error (CWE-346) in the DNS service in Windows, where the DNS server does not adequately verify the origin of network responses it accepts. An unauthorized remote attacker who can reach the DNS service over a network can send crafted traffic to perform spoofing, though the high attack complexity in the CVSS vector (AC:H) means successful exploitation likely requires favorable network conditions or timing. A successful spoofing attack can compromise the integrity, confidentiality, and availability of DNS resolution (all rated high in the CVSS impact metrics), potentially causing clients to receive forged name-resolution data. Any organization running the DNS role on Windows, most commonly on DNS servers and Active Directory domain controllers, is potentially affected. As of this analysis there is no known exploitation, no public proof-of-concept, no KEV listing, and EPSS puts 30-day exploitation probability at only 0.3%.
What to do: Install the Microsoft security update addressing CVE-2026-69680 as soon as it is available through normal Windows update channels. Until patched, restrict inbound TCP/UDP 53 to Windows DNS servers from trusted networks and clients only, and audit whether any DNS servers (especially resolvers) are internet-exposed or reachable from untrusted network segments. Prioritize patching domain controllers and externally reachable resolvers, since those handle the highest volumes of resolution traffic.
| Microsoft Windows DNS (DNS Server role) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Origin validation error in Windows DNS allows an unauthorized attacker to perform spoofing over a network.
- Weakness
- CWE-346
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.