CVE-2026-48564
DHCP Server Service Remote Code Execution Vulnerability
Description
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
In plain language
AI Act nowCVE-2026-48564 is a Windows DHCP Server bug that can let an attacker remotely run code on your network servers; if you run DHCP Server on affected Windows versions, you should act now because a fix is available.
CVE-2026-48564 is a heap-based buffer overflow in the Windows DHCP Server that can lead to remote code execution over the network, with low attacker effort and no sign-in required; Microsoft has fixed multiple affected Windows releases.
What to do now
- Check whether your organization runs the Windows DHCP Server role on any of these: windows 10, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025, windows server 2012 r2.
- For windows 10, upgrade to 10.0.14393.9339 or 10.0.17763.9020.
- For windows server 2012, upgrade to 6.2.9200.26132.
- For windows server 2012 r2, upgrade to 6.3.9600.23228.
- For windows server 2016, upgrade to 10.0.14393.9339.
- For windows server 2019, upgrade to 10.0.17763.9020.
- For windows server 2022, upgrade to 10.0.20348.5386.
- For windows server 2025, upgrade to 10.0.26100.33158.
- Apply the Microsoft update from the official Microsoft Update Guide for CVE-2026-48564, then verify the updated version is installed on each affected machine.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft and Adobe Patch Tuesday, July 2026 Security Update Reviewen-us·Qualys Security Blog· Patch Windows patch-tuesday
- Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Active Directory Federation Services (AD FS) rce
- Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Hereen·SANS Internet Storm Center· Exploited Windows privilege-escalation
- Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-daysen-us·BleepingComputer· Exploited .NET zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-48564 and every CVE in our database. Create a free account — no credit card required.
Create Free Account