CVE-2026-62820
Windows DNS Server Remote Code Execution Vulnerability
Description
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.
In plain language
AI Act nowThis is a Windows DNS Server flaw that lets an attacker, with no login needed, try to remotely run malicious code; most small businesses should treat it as urgent because it’s reachable in default setups and can be hit without user action.
Unauthenticated remote code execution via a timing (race condition) flaw in the Windows DNS Server’s handling of shared resources; attackers trigger the issue over the network without any authentication or user interaction.
What to do now
- Check whether you run Windows DNS Server on Windows 10, Windows Server 2016, 2019, 2022, or 2025 (or whether these machines provide DNS services for your business).
- If affected, upgrade/install the vendor fixes immediately: Windows 10 fixed in 10.0.14393.9418 or 10.0.17763.9121; Windows Server 2016 fixed in 10.0.14393.9418; Windows Server 2019 fixed in 10.0.17763.9121; Windows Server 2022 fixed in 10.0.20348.5499; Windows Server 2025 fixed in 10.0.26100.33296.
- Verify the DNS role/service remains on the patched build and confirm your DNS is still functioning normally after updates.
- If you cannot patch right away, reduce exposure by restricting network access to your DNS services (allow only the needed internal/management networks) until the fixed versions are applied.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62820 and every CVE in our database. Create a free account — no credit card required.
Create Free Account