CVE-2026-72979
Windows DHCP Server Remote Code Execution Vulnerability
Description
Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
In plain language
AI Act nowIf your business runs the Windows DHCP Server role, this serious bug can let a remote attacker execute code over the network—so you should act now to get the fixed Windows update.
CVE-2026-72979 is a Windows DHCP Server remote code execution vulnerability caused by a use-after-free weakness; attackers can trigger it by sending crafted network DHCP traffic to a DHCP server that is reachable.
What to do now
- Check whether you run the Windows DHCP Server role on any machines (especially if they are reachable by other networks/clients).
- Identify the exact Windows version/build number on those DHCP servers.
- Compare your build to the fixed versions and plan an upgrade/patch to match one of the following: Windows 10 10.0.14393.9512 or 10.0.17763.9245; Windows Server 2012 6.2.9200.26349; Windows Server 2012 R2 6.3.9600.23397; Windows Server 2016 10.0.14393.9512; Windows Server 2019 10.0.17763.9245; Windows Server 2022 10.0.20348.5622; Windows Server 2025 10.0.26100.33438.
- Install the Microsoft security update for CVE-2026-72979 from the update guide page and reboot if required.
- Verify the patch is applied by re-checking the Windows version/build after installation.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Daysen·The Hacker News· Exploited Windows zero-day
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows zero-day
- Microsoft and Adobe Patch Tuesday, September 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Microsoft Exchange Server Qualys
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysen-us·BleepingComputer· Exploited Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-72979 and every CVE in our database. Create a free account — no credit card required.
Create Free Account