CVE-2026-77494
largeUnauthenticated DoS via type confusion in Microsoft Windows DHCP Server
CVE-2026-77494 is a type confusion flaw (CWE-843) in the Windows DHCP Server service, where the service accesses a resource using an incompatible type. A remote, unauthenticated attacker can trigger it by sending crafted network traffic to a DHCP Server, with no privileges or user interaction required. Successful exploitation causes high-impact loss of availability — the DHCP service can fail or become unavailable, preventing clients from obtaining IP leases — with no stated confidentiality or integrity impact. Any organization running the DHCP Server role on Windows Server is potentially affected; specific affected version ranges are not listed in the available data and should be taken from Microsoft's advisory. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 1.2% chance of exploitation within 30 days.
What to do: Identify the affected Windows Server versions in Microsoft's advisory for CVE-2026-77494 and apply the corresponding security update. As an interim mitigation, restrict reachability of the DHCP service (UDP 67/68) to trusted network segments and monitor DHCP service health for unexpected restarts. Since there is no known exploitation, public PoC, or KEV listing, patching can follow your normal cycle, but prioritize internet-reachable or critical DHCP servers given the unauthenticated remote attack vector.
| Microsoft Windows DHCP Server (Windows Server) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
- Weakness
- CWE-843
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.