ZeroHour

CVE-2026-69680

mass

Origin Validation Flaw in Windows DNS Enables Network Spoofing

CVSS 3.1
8.1 high
EPSS
<1%p28
Published
()
Modified
AI analysis

CVE-2026-69680 is an origin validation error (CWE-346) in the DNS service in Windows, where the DNS server does not adequately verify the origin of network responses it accepts. An unauthorized remote attacker who can reach the DNS service over a network can send crafted traffic to perform spoofing, though the high attack complexity in the CVSS vector (AC:H) means successful exploitation likely requires favorable network conditions or timing. A successful spoofing attack can compromise the integrity, confidentiality, and availability of DNS resolution (all rated high in the CVSS impact metrics), potentially causing clients to receive forged name-resolution data. Any organization running the DNS role on Windows, most commonly on DNS servers and Active Directory domain controllers, is potentially affected. As of this analysis there is no known exploitation, no public proof-of-concept, no KEV listing, and EPSS puts 30-day exploitation probability at only 0.3%.

What to do: Install the Microsoft security update addressing CVE-2026-69680 as soon as it is available through normal Windows update channels. Until patched, restrict inbound TCP/UDP 53 to Windows DNS servers from trusted networks and clients only, and audit whether any DNS servers (especially resolvers) are internet-exposed or reachable from untrusted network segments. Prioritize patching domain controllers and externally reachable resolvers, since those handle the highest volumes of resolution traffic.

Affected
Microsoft Windows DNS (DNS Server role)
Estimated exposure
massmillions of installations (the DNS Server role is standard on Windows Server domain controllers and DNS infrastructure servers) — The DNS role ships with Windows Server and is typically deployed on every Active Directory domain controller plus standalone DNS servers, and global Windows Server installations number in the millions, although only a subset of these are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Origin validation error in Windows DNS allows an unauthorized attacker to perform spoofing over a network.

Weakness
CWE-346
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.