ZeroHour

CVE-2026-72979

mass

Unauthenticated Use-After-Free RCE in Windows DHCP Server

CVSS 3.1
9.8 critical
EPSS
<1%p60
Published
()
Modified
AI analysis

CVE-2026-7296 is a use-after-free memory-corruption flaw (CWE-416) in the Windows DHCP Server role, rated critical (CVSS 9.8). An unauthenticated attacker can trigger it by sending network traffic to the DHCP service, with no credentials or user interaction required. Successful exploitation allows arbitrary code execution on the DHCP server, with high impact on confidentiality, integrity, and availability per the CVSS vector. Any Windows Server with the DHCP Server role enabled is affected; the available data does not enumerate specific affected or fixed build numbers. As of the September 2026 Patch Tuesday release (which patched a record 974 flaws, including two separately exploited Windows zero-days), there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates roughly a 1% probability of exploitation within 30 days.

What to do: Apply the September 2026 Microsoft security updates to every Windows Server with the DHCP Server role, prioritizing servers reachable from untrusted networks such as guest Wi-Fi, branch, and edge sites. Until patched, restrict DHCP traffic (UDP ports 67 and 68) to trusted network segments and monitor for anomalous DHCP activity. Inventory the role on your estate (e.g., via Windows Server role/DHCP server audits) to confirm patch coverage.

Affected
Microsoft Windows Server (DHCP Server role)
Estimated exposure
masshundreds of thousands to low millions of Windows DHCP Server deployments worldwide; only a small fraction directly internet-exposed — DHCP Server is one of the most commonly deployed Windows Server infrastructure roles, typically running at one or more instances per enterprise or branch site across the very large global Windows Server installed base, though the service…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

Microsoft's September Patch Tuesday fixed a record 974 flaws, including two Windows privilege-escalation zero-days actively exploited and added to CISA's KEV catalog.

Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities (999 including 25 non-Microsoft CVEs), with over 110 rated critical; 723 affect Windows and 111 affect Office. Two Windows privilege-escalation zero-days are actively exploited: CVE-2026-85880, an ALPC heap-based buffer overflow, and CVE-2026-81963, an improper link resolution flaw in the Windows Update Stack, both allowing attackers to gain SYSTEM privileges. CISA added both flaws to its KEV catalog, giving federal civilian agencies until September 22, 2026 to apply fixes. Volexity, Proofpoint, MSTIC, and independent researchers were credited with the reports; notable additional fixes include network-reachable RCEs in Exchange, SharePoint, SQL Server, Remote Desktop Services, DNS, and DHCP.

The Hacker News · 6d agoExploit / PoC in the wildCVE-2026-85880CVE-2026-81963CVE-2026-55007+9 CVEs

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including 113 critical, with two Windows privilege-escalation bugs (CVE-2026-81963, CVE-2026-85880) exploited in the wild.

Microsoft's September 2026 security update addresses 973 vulnerabilities across its product lineup, 113 rated critical, of which 82 are remote code execution flaws. Two vulnerabilities are confirmed exploited in the wild: CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack (CVSS 7.8), and CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (CVSS 7.8). Microsoft flags several bugs as more likely to be exploited, including a 9.8 RCE in Windows DNS Server (CVE-2026-69730), an 8.8 RCE in Windows Kerberos (CVE-2026-69676), and a 9.0 EoP in Spring Cloud Azure (CVE-2026-69854). Cisco Talos published accompanying Snort rules to detect exploitation attempts against the prominent flaws.

Cisco Talos · 7d agoAdvisory in the wildCVE-2026-81963CVE-2026-85880CVE-2026-69676+27 CVEs