Microsoft's Record 972-CVE Patch Tuesday Buried a SigRed Successor. It's Not One of the Confirmed Zero-Days.
CVE-2026-69730 needs no password and no click to take over a domain's DNS server. Two other bugs in the same release are confirmed under active attack — this one isn't, yet.

On September 8, 2026, Microsoft shipped the largest security update in its history — and buried inside it is a bug that needs no password, no click, and no skill beyond sending a network packet to take over a domain's DNS server. It isn't one of the two vulnerabilities Microsoft confirmed attackers are actively using. That's the part worth paying attention to.
What SigRed Was, and Why the Comparison Matters
SigRed (CVE-2020-1350) was a maximum-severity, wormable use-after-free in Windows DNS Server, disclosed and patched by Microsoft in July 2020. It let an unauthenticated attacker who could reach a domain controller's DNS service send a single crafted DNS response and get Local System-level code execution — no credentials, no user interaction, and by design capable of spreading itself server to server. It never produced a global worm, but it kept incident responders on emergency footing for months and became the reference point for "this could be the next big one." Zero Day Initiative's Dustin Childs invoked that reference point directly for CVE-2026-69730, calling it DNS Server's spiritual successor to SigRed.
The Bug Itself
CVE-2026-69730 is a use-after-free (CWE-416) in the Windows DNS Server role. Microsoft's advisory describes it plainly: an unauthorized attacker can execute code over a network. The CVSS 3.1 vector — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — means every precondition an attacker needs is already met by default: no authentication, low attack complexity, no user interaction, and full compromise of confidentiality, integrity and availability if it lands. What it doesn't have, as of this writing, is a public proof-of-concept or confirmed exploitation. Our own index puts its EPSS score at just 1.05% — the 62.8th percentile, nowhere near the double-digit scores that usually accompany a CVSS 9.8 with real attacker interest. That gap between theoretical severity and observed interest is exactly the window ZDI is warning about.
| Product | Vulnerable range | Fixed build |
|---|---|---|
| Windows Server 2012 | 6.2.9200.0 – <6.2.9200.26349 | 6.2.9200.26349 |
| Windows Server 2012 R2 | 6.3.9600.0 – <6.3.9600.23397 | 6.3.9600.23397 |
| Windows Server 2016 / Windows 10 v1607 | 10.0.14393.0 – <10.0.14393.9512 | 10.0.14393.9512 |
| Windows Server 2019 / Windows 10 v1809 | 10.0.17763.0 – <10.0.17763.9245 | 10.0.17763.9245 |
| Windows Server 2022 | 10.0.20348.0 – <10.0.20348.5622 | 10.0.20348.5622 |
| Windows Server 2025 | 10.0.26100.0 – <10.0.26100.33438 | 10.0.26100.33438 |
Two Bugs, Same Component, Different Severity
CVE-2026-69730 wasn't the only Windows DNS Server fix in September's release. CVE-2026-69858 is a second use-after-free in the same component, also on ZDI's wormable list and patched the same day — but scored 8.1 rather than 9.8 in our index, one notch below Critical. Microsoft's own description of the two bugs is nearly identical; the practical gap between an 8.1 and a 9.8 on the same component is a reminder that CVSS sub-scores can diverge sharply even when the underlying flaw class is the same.
Why the Scarier Bug Is Getting Less Attention
Two vulnerabilities in September's Patch Tuesday are confirmed to be under active attack. Neither of them is CVE-2026-69730.
Confirmed Exploited vs. Theoretically Worse
- CVSS 9.8 — maximum practical severity
- Unauthenticated, zero user interaction, network-reachable
- Wormable — grouped with 20 such bugs this month, per ZDI
- EPSS just 1.05%, 62.8th percentile in our index
- No public proof-of-concept in our index
- Not confirmed exploited by Microsoft or CISA as of writing
- CVSS 7.8 each — High, not Critical
- Both are local privilege-escalation bugs, not remote code execution
- CVE-2026-85880 requires user interaction, e.g. opening a malicious file
- Both confirmed exploited in the wild per Microsoft's own advisories
- Likely paired with a separate delivery bug for real-world use, per ZDI
- The only two confirmed zero-days out of 972 new CVEs this month
The Database Still Says No Fix Exists
What To Do About It
- Apply the September 2026 cumulative update to every Windows Server running the DNS Server role — 2012 through 2025, physical or virtual, Server Core included.
- Prioritize domain controllers and any DNS server reachable from outside a trusted network segment; SigRed's real-world impact came from domain controllers specifically.
- Don't treat has_exploit: false as a reason to deprioritize — EPSS and PoC status can flip fast once a well-publicized bug draws researcher attention.
- Patch CVE-2026-69858 in the same maintenance window — it's a second use-after-free in the same component, on the same wormable list.
- If DNS Server can't be patched immediately, restrict network reachability to only the hosts and services that need to query it.
From SigRed to Its Successor
- SigRed (CVE-2020-1350) disclosed and patchedA maximum-severity, wormable use-after-free in Windows DNS Server — the reference point every later DNS Server bug gets measured against.
- Microsoft ships fix for CVE-2026-69730Published as part of a record 972-new-CVE Patch Tuesday, alongside a second DNS Server use-after-free, CVE-2026-69858.
- ZDI calls it SigRed's spiritual successorDustin Childs groups it with 20 wormable bugs in the same release and flags it for priority patching.
- Still no public PoC, no confirmed exploitationAs of this writing, neither Microsoft nor CISA lists CVE-2026-69730 as exploited, and no proof-of-concept exists in our index.
Is CVE-2026-69730 being actively exploited?
What does "wormable" mean here?
Is this the same bug as SigRed?
Why does the CVSS score matter more than the EPSS score here?
No confirmed exploitation as of September 19, 2026live record →