CVE Tools
Back to blog

Microsoft's Record 972-CVE Patch Tuesday Buried a SigRed Successor. It's Not One of the Confirmed Zero-Days.

CVE-2026-69730 needs no password and no click to take over a domain's DNS server. Two other bugs in the same release are confirmed under active attack — this one isn't, yet.

Microsoft's Record 972-CVE Patch Tuesday Buried a SigRed Successor. It's Not One of the Confirmed Zero-Days.. CVE-2026-69730 needs no password and no click to take over a domain's DNS server. Two othe
Microsoft's Record 972-CVE Patch Tuesday Buried a SigRed Successor. It's Not One of the Confirmed Zero-Days.. CVE-2026-69730 needs no password and no click to take over a domain's DNS server. Two othe

On September 8, 2026, Microsoft shipped the largest security update in its history — and buried inside it is a bug that needs no password, no click, and no skill beyond sending a network packet to take over a domain's DNS server. It isn't one of the two vulnerabilities Microsoft confirmed attackers are actively using. That's the part worth paying attention to.

972new CVEs in September's Patch Tuesday997 incl. Chromium/third-party — Zero Day Initiative
20wormable bugs in one releaseunauthenticated, no user interaction — Dustin Childs, ZDI
9.8CVSS for CVE-2026-69730use-after-free, Windows DNS Server, no public PoC yet

What SigRed Was, and Why the Comparison Matters

SigRed (CVE-2020-1350) was a maximum-severity, wormable use-after-free in Windows DNS Server, disclosed and patched by Microsoft in July 2020. It let an unauthenticated attacker who could reach a domain controller's DNS service send a single crafted DNS response and get Local System-level code execution — no credentials, no user interaction, and by design capable of spreading itself server to server. It never produced a global worm, but it kept incident responders on emergency footing for months and became the reference point for "this could be the next big one." Zero Day Initiative's Dustin Childs invoked that reference point directly for CVE-2026-69730, calling it DNS Server's spiritual successor to SigRed.

The Bug Itself

CVE-2026-69730 is a use-after-free (CWE-416) in the Windows DNS Server role. Microsoft's advisory describes it plainly: an unauthorized attacker can execute code over a network. The CVSS 3.1 vector — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — means every precondition an attacker needs is already met by default: no authentication, low attack complexity, no user interaction, and full compromise of confidentiality, integrity and availability if it lands. What it doesn't have, as of this writing, is a public proof-of-concept or confirmed exploitation. Our own index puts its EPSS score at just 1.05% — the 62.8th percentile, nowhere near the double-digit scores that usually accompany a CVSS 9.8 with real attacker interest. That gap between theoretical severity and observed interest is exactly the window ZDI is warning about.

ProductVulnerable rangeFixed build
Windows Server 20126.2.9200.0 – <6.2.9200.263496.2.9200.26349
Windows Server 2012 R26.3.9600.0 – <6.3.9600.233976.3.9600.23397
Windows Server 2016 / Windows 10 v160710.0.14393.0 – <10.0.14393.951210.0.14393.9512
Windows Server 2019 / Windows 10 v180910.0.17763.0 – <10.0.17763.924510.0.17763.9245
Windows Server 202210.0.20348.0 – <10.0.20348.562210.0.20348.5622
Windows Server 202510.0.26100.0 – <10.0.26100.3343810.0.26100.33438

Two Bugs, Same Component, Different Severity

CVE-2026-69730 wasn't the only Windows DNS Server fix in September's release. CVE-2026-69858 is a second use-after-free in the same component, also on ZDI's wormable list and patched the same day — but scored 8.1 rather than 9.8 in our index, one notch below Critical. Microsoft's own description of the two bugs is nearly identical; the practical gap between an 8.1 and a 9.8 on the same component is a reminder that CVSS sub-scores can diverge sharply even when the underlying flaw class is the same.

Why the Scarier Bug Is Getting Less Attention

Two vulnerabilities in September's Patch Tuesday are confirmed to be under active attack. Neither of them is CVE-2026-69730.

Confirmed Exploited vs. Theoretically Worse

CVE-2026-69730 (DNS Server RCE)
  • CVSS 9.8 — maximum practical severity
  • Unauthenticated, zero user interaction, network-reachable
  • Wormable — grouped with 20 such bugs this month, per ZDI
  • EPSS just 1.05%, 62.8th percentile in our index
  • No public proof-of-concept in our index
  • Not confirmed exploited by Microsoft or CISA as of writing
We haven't seen a global worm in years, but that could change quickly. — Dustin Childs, ZDI
CVE-2026-81963 and CVE-2026-85880
  • CVSS 7.8 each — High, not Critical
  • Both are local privilege-escalation bugs, not remote code execution
  • CVE-2026-85880 requires user interaction, e.g. opening a malicious file
  • Both confirmed exploited in the wild per Microsoft's own advisories
  • Likely paired with a separate delivery bug for real-world use, per ZDI
  • The only two confirmed zero-days out of 972 new CVEs this month
These bugs must be triggered by the user. Assume they are coming for you and patch quickly. — Dustin Childs, ZDI

The Database Still Says No Fix Exists

What To Do About It

  1. Apply the September 2026 cumulative update to every Windows Server running the DNS Server role — 2012 through 2025, physical or virtual, Server Core included.
  2. Prioritize domain controllers and any DNS server reachable from outside a trusted network segment; SigRed's real-world impact came from domain controllers specifically.
  3. Don't treat has_exploit: false as a reason to deprioritize — EPSS and PoC status can flip fast once a well-publicized bug draws researcher attention.
  4. Patch CVE-2026-69858 in the same maintenance window — it's a second use-after-free in the same component, on the same wormable list.
  5. If DNS Server can't be patched immediately, restrict network reachability to only the hosts and services that need to query it.

From SigRed to Its Successor

  1. SigRed (CVE-2020-1350) disclosed and patched
    A maximum-severity, wormable use-after-free in Windows DNS Server — the reference point every later DNS Server bug gets measured against.
  2. Microsoft ships fix for CVE-2026-69730
    Published as part of a record 972-new-CVE Patch Tuesday, alongside a second DNS Server use-after-free, CVE-2026-69858.
  3. ZDI calls it SigRed's spiritual successor
    Dustin Childs groups it with 20 wormable bugs in the same release and flags it for priority patching.
  4. Still no public PoC, no confirmed exploitation
    As of this writing, neither Microsoft nor CISA lists CVE-2026-69730 as exploited, and no proof-of-concept exists in our index.
Is CVE-2026-69730 being actively exploited?
Not as of this writing. Microsoft has not flagged it as exploited, it isn't on CISA's Known Exploited Vulnerabilities catalog, and our own index shows no public proof-of-concept. The two confirmed zero-days from September's Patch Tuesday — CVE-2026-81963 and CVE-2026-85880 — are unrelated local privilege-escalation bugs, not this one.
What does "wormable" mean here?
Zero Day Initiative uses it for bugs that need no authentication and no user interaction to trigger remotely — the same precondition profile that let flaws like SigRed spread from system to system without anyone clicking anything.
Is this the same bug as SigRed?
No. SigRed (CVE-2020-1350) was patched in July 2020. CVE-2026-69730 is a distinct 2026 use-after-free in the same Windows DNS Server component — ZDI's comparison is about severity and exploitability profile, not a shared root cause.
Why does the CVSS score matter more than the EPSS score here?
EPSS estimates the probability of exploitation in the next 30 days based on observed attacker activity — for a bug with no public PoC yet, that number will always look low right up until it doesn't. CVSS measures what happens if it is exploited. For an unauthenticated, wormable DNS Server RCE, that ceiling is the number worth planning around.

No confirmed exploitation as of September 19, 2026live record →

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store