CVE Tools

CVE-2026-65789

Windows DNS Server Remote Code Execution Vulnerability

Published: Aug 11, 2026Updated: Aug 17, 2026 Sources: CVE List NVDCWE-416

Description

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

In plain language

AI Act now

CVE-2026-65789 is a Windows DNS server flaw that can let someone on the network take over (or crash) your server without logging in—if you run Windows DNS, you should treat this as urgent and apply the fixed updates for your version.

Executive summary

CVE-2026-65789 is a Windows DNS Server remote code execution vulnerability triggered by sending specially crafted network packets that exploit a memory management flaw (use-after-free), allowing arbitrary code execution with no authentication or user interaction.

If affected, business impact
Server takeoverService disruption (DNS outage)Domain/account disruption riskWorm-like spread risk inside networks

What to do now

  1. Check whether your organization runs Windows DNS Server (and which Windows version/build it uses).
  2. If you run Windows DNS on any of: Windows 10, Windows Server 2016, Windows Server 2019, Windows Server 2022, Windows Server 2025, update immediately to the fixed versions listed below.
  3. Verify DNS is reachable from any untrusted network path you allow (internet-facing, VPN-bridged, or exposed management networks); reduce exposure if present.
  4. After updating, confirm Windows DNS services are running normally and monitor for unusual DNS traffic or crashes.
Usually a quick update

CVSS Vector Breakdown

AV:NAC:HPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:HAttack Complexity
High
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 10 more affected products View all →

Exploitability

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Initial Access
Privilege Escalation
View detailed technique mapping

References

4

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-65789 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows