CVE-2026-69730
Windows DNS Server Remote Code Execution Vulnerability
Description
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
In plain language
AI Act nowCVE-2026-69730 is a Windows DNS Server bug that can let an attacker run code remotely; if you run DNS on the affected Windows versions, you should patch now.
CVE-2026-69730 is a remote code execution vulnerability in Windows DNS (CWE-416 use-after-free), triggered by crafted network requests to the DNS service that can lead to unauthorized code execution without authentication.
What to do now
- Identify whether your organization is running Windows DNS on any of these systems: Windows 10, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, or Windows Server 2025.
- For each affected system, check the OS build/revision against the fixed versions listed by Microsoft.
- Patch each affected machine using Microsoft’s update for CVE-2026-69730, upgrading to the exact fixed version for your OS branch:
- Windows 10: 10.0.14393.9512 or 10.0.17763.9245
- Windows Server 2012: 6.2.9200.26349
- Windows Server 2012 R2: 6.3.9600.23397
- Windows Server 2016: 10.0.14393.9512
- Windows Server 2019: 10.0.17763.9245
- Windows Server 2022: 10.0.20348.5622
- Windows Server 2025: 10.0.26100.33438
- After patching, confirm the DNS service is operating normally and that the system has successfully installed the security update from Microsoft’s update guidance for CVE-2026-69730.
- If you cannot patch immediately, reduce exposure by restricting network access to the DNS service (only allow required DNS clients) and monitor DNS-related logs for suspicious activity until patching is completed.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successoren-us·Help Net Security· Exploited Windows Update Stack patch-tuesday
- Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Daysen·The Hacker News· Exploited Windows zero-day
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows zero-day
- Microsoft Plugs Nearly 1,000 Security Holes – Krebs on Securityen-us·Krebs on Security· Exploited Windows zero-day
- Patch Tuesday Sets Another Record With 974 CVEsen·Dark Reading· Exploited Windows zero-day
- Microsoft and Adobe Patch Tuesday, September 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Microsoft Exchange Server Qualys
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysen-us·BleepingComputer· Exploited Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-69730 and every CVE in our database. Create a free account — no credit card required.
Create Free Account