CVE-2026-62878
Windows DNS Server Remote Code Execution Vulnerability
Description
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
In plain language
AI Act nowThis is a serious Windows DNS Server security flaw that could let an attacker take full control of the DNS service from across the network—so most businesses using affected Windows Server/Windows 10 versions should act quickly to install the fixed updates.
CVE-2026-62878 is a Windows DNS Server remote code execution vulnerability (CWE-121: stack-based buffer overflow) enabling unauthorized network attackers to execute code, with press attention tied to exploitation by Lazarus group despite no KEV listing or public exploit code on record.
What to do now
- Check whether you run Windows DNS Server (or any Windows host exposing DNS services) on the affected Windows versions: Windows 10, and Windows Server 2012/2012 R2/2016/2019/2022/2025.
- For each affected machine, compare your installed patch level to the fixed versions below and determine if you are already patched.
- Install the vendor updates from Microsoft Update Guide for CVE-2026-62878.
- After patching, restart the affected DNS service (and reboot if required by the update) and confirm the updated version is now in place.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft выпустила патчи более чем для 400 уязвимостейru-ru·Хакер (xakep.ru)· Exploited Windows Lazarus
- Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)en-us·Help Net Security· Exploited Windows Lazarus Group
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft's Patch Tuesday Deluge Continues With August Updatesen·Dark Reading· Exploited Windows patch-tuesday
- Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attacken·The Hacker News· Exploited Windows Lazarus Group
- August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Dayen-us·SecurityWeek· Exploited Windows Lazarus group
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62878 and every CVE in our database. Create a free account — no credit card required.
Create Free Account