• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-62878: pre-auth remote code execution in Microsoft Windows Server 2012

An unauthenticated attacker can execute arbitrary code over a network against Windows Server DNS by triggering a stack-based buffer overflow. CVE-2026-62878 affects multiple Windows Server releases, including Windows Server 2012 and 2012 R2, Windows Server 2016, 2019, 2022 and 2025 in the listed build ranges; an attacker needs only network access and does not require valid credentials to exploit the flaw. Vendor fixes are available for the affected builds.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-121
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent—public exploit code exists for an unauthenticated remote code execution flaw in Windows DNS, so prioritize installing the vendor fixes or isolating DNS servers from untrusted networks immediately.

What is CVE-2026-62878?

An unauthenticated attacker can execute arbitrary code over a network against Windows Server DNS by triggering a stack-based buffer overflow. CVE-2026-62878 affects multiple Windows Server releases, including Windows Server 2012 and 2012 R2, Windows Server 2016, 2019, 2022 and 2025 in the listed build ranges; an attacker needs only network access and does not require valid credentials to exploit the flaw. Vendor fixes are available for the affected builds.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows Server 2012 are affected?

BRANCHAFFECTEDFIXED
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.262806.2.9200.26280
Windows Server 2012 (Server Core installation) 6.x6.2.9200.0 – before 6.2.9200.262806.2.9200.26280
Windows Server 2012 R2 6.x6.3.9600.0 – before 6.3.9600.233386.3.9600.23338
Windows Server 2012 R2 (Server Core installation) 6.x6.3.9600.0 – before 6.3.9600.233386.3.9600.23338
Windows Server 2016 10.x10.0.14393.0 – before 10.0.14393.941810.0.14393.9418
Windows Server 2016 (Server Core installation) 10.x10.0.14393.0 – before 10.0.14393.941810.0.14393.9418
Windows Server 2019 10.x10.0.17763.0 – before 10.0.17763.912110.0.17763.9121
Windows Server 2019 (Server Core installation) 10.x10.0.17763.0 – before 10.0.17763.912110.0.17763.9121
Windows Server 2022 10.x10.0.20348.0 – before 10.0.20348.549910.0.20348.5499
Windows Server 2025 10.x10.0.26100.0 – before 10.0.26100.3329610.0.26100.33296

Is CVE-2026-62878 being exploited?

Public exploit code is available for CVE-2026-62878.

How to fix CVE-2026-62878

  1. Apply Microsoft updates that contain the fixes: 6.2.9200.26280, 6.3.9600.23338, 10.0.14393.9418, 10.0.17763.9121, 10.0.20348.5499, or 10.0.26100.33296 as appropriate for your build.
  2. If immediate patching is not possible, restrict network exposure of DNS servers to trusted networks and block untrusted access at firewalls.
  3. Follow vendor guidance to verify update installation and restart DNS services or hosts as directed.
  4. Monitor DNS server logs and network traffic for anomalous queries and signs of exploitation and hunt for indicators of compromise.

Frequently asked questions

Is CVE-2026-62878 being actively exploited?

Public exploit code is available for CVE-2026-62878; there is no CISA Known Exploited Vulnerabilities listing as of 2026-09-29.

Which Windows Server versions are affected by CVE-2026-62878?

The vulnerability affects Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025 builds in the ranges listed by the vendor; consult the affected build ranges to confirm whether your server build is vulnerable.

Is there a patch for CVE-2026-62878?

Yes. Microsoft published updates that fix the issue; apply the fixed builds (for example 6.2.9200.26280, 6.3.9600.23338, 10.0.14393.9418, 10.0.17763.9121, 10.0.20348.5499, 10.0.26100.33296) matching your OS build.

Does CVE-2026-62878 require authentication?

No. The flaw is exploitable without authentication against Windows DNS according to the vendor description.

References