CVE-2026-69876
massUse-After-Free RCE in Microsoft Windows DHCP Server
CVE-2026-69876 is a use-after-free memory-corruption flaw in the DHCP Server role of Microsoft Windows (also tagged with CWE-415, double free). An authorized attacker positioned on an adjacent network segment can send crafted DHCP service traffic that causes the server to reuse freed memory, corrupting the process and leading to arbitrary code execution. Successful exploitation gives the attacker code execution on the DHCP server with high impact on confidentiality, integrity, and availability, and DHCP servers are core infrastructure often co-located with domain controllers, so a foothold there is a useful pivot point. Any organization running the DHCP Server role on Windows Server is potentially affected, though the flaw is limited to authorized, adjacent-network attackers rather than unauthenticated remote attackers. There is currently no known exploitation: the CVE is not in CISA KEV, has a low EPSS score (0.6%, 46th percentile), and no public proof-of-concept is known.
What to do: Inventory servers with the DHCP Server role enabled (e.g., via your configuration-management or Windows feature inventory) and apply Microsoft's security update for this CVE as soon as it is released, checking the MSRC advisory and the next Patch Tuesday. Until patched, limit which network segments and devices can reach the DHCP service on these servers and monitor for DHCP service crashes or restarts. Given the adjacent-network, authorized-attacker requirement and the low EPSS score, treat this as a standard-priority patch, prioritizing DHCP servers on core or broadly reachable segments.
| Microsoft Windows DHCP Server (DHCP Server role in Windows Server) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-415, CWE-416
- Vector
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.