CVE-2026-62823
Windows DHCP Server Remote Code Execution Vulnerability
Description
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
In plain language
AI Act nowThis Windows DHCP Server flaw could let an attacker remotely take over a machine on the network—if you run DHCP on Windows Server (or Windows 10) and it’s reachable from other networks, you should patch right away.
CVE-2026-62823 is a Windows DHCP Server remote code execution vulnerability (CWE-122, heap-based buffer overflow) that can be triggered by a remote, unauthorized attacker interacting with DHCP server behavior over the network.
What to do now
- Check whether you are running Windows DHCP Server (or any Windows device acting as a DHCP server) in the affected product list.
- Identify your exact OS version (e.g., Windows Server 2019 build, Windows 10 build) and compare it to the fixed version numbers below.
- Upgrade/patch immediately to one of the fixed versions:
- Windows 10: fixed in 10.0.14393.9418 or 10.0.17763.9121 (and 10.0.17763.9115 for the relevant servicing branch)
- Windows Server 2012: fixed in 6.2.9200.26280
- Windows Server 2012 R2: fixed in 6.3.9600.23338
- Windows Server 2016: fixed in 10.0.14393.9418
- Windows Server 2019: fixed in 10.0.17763.9121 (and 10.0.17763.9115 for the relevant servicing branch)
- Windows Server 2022: fixed in 10.0.20348.5499 (and 10.0.20348.5440 for the relevant servicing branch)
- Windows Server 2025: fixed in 10.0.26100.33296 (and 10.0.26100.33222 for the relevant servicing branch)
- If patching must be delayed, restrict who can reach the DHCP server from other networks (network segmentation/firewall rules) until the fixed update is installed.
CVSS Vector Breakdown
AV:AAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62823 and every CVE in our database. Create a free account — no credit card required.
Create Free Account