CVE-2026-56159
DHCP Server Service Remote Code Execution Vulnerability
Description
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
In plain language
AI Act nowCVE-2026-56159 is a critical remote code execution weakness in the Windows DHCP Server service, and you should act now if your business runs DHCP Server on any listed Windows version because an attacker may be able to take control over the network.
CVE-2026-56159 is a heap-based buffer overflow in the Windows DHCP Server service that can be triggered remotely, allowing unauthorized attackers to execute code over the network without needing credentials.
What to do now
- Check whether this server runs the Windows DHCP Server service (the DHCP role/service), not just whether DHCP client is used.
- Identify the exact Windows edition and version (Windows 10 / Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025) and confirm your current OS build/patch level.
- Compare your version/build against the fixed versions; if you are at or below the affected level, schedule the Windows update for CVE-2026-56159 immediately.
- Upgrade/patch to the fixed version for your branch: Windows 10 → 10.0.14393.9339 or 10.0.17763.9020; Windows Server 2012 → 6.2.9200.26226; Windows Server 2012 R2 → 6.3.9600.23291; Windows Server 2016 → 10.0.14393.9339; Windows Server 2019 → 10.0.17763.9020; Windows Server 2022 → 10.0.20348.5386; Windows Server 2025 → 10.0.26100.33158.
- If you cannot patch right away, restrict access so only trusted admin networks can reach the DHCP server service (and consider stopping/disabling the DHCP Server role where feasible).
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft and Adobe Patch Tuesday, July 2026 Security Update Reviewen-us·Qualys Security Blog· Patch Windows patch-tuesday
- Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Active Directory Federation Services (AD FS) rce
- Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Hereen·SANS Internet Storm Center· Exploited Windows privilege-escalation
- Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-daysen-us·BleepingComputer· Exploited .NET zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-56159 and every CVE in our database. Create a free account — no credit card required.
Create Free Account