DIRAS TAKE
Urgent—public exploit code exists for an unauthenticated remote code execution flaw in Windows DNS, so prioritize installing the vendor fixes or isolating DNS servers from untrusted networks immediately.
What is CVE-2026-62878?
An unauthenticated attacker can execute arbitrary code over a network against Windows Server DNS by triggering a stack-based buffer overflow. CVE-2026-62878 affects multiple Windows Server releases, including Windows Server 2012 and 2012 R2, Windows Server 2016, 2019, 2022 and 2025 in the listed build ranges; an attacker needs only network access and does not require valid credentials to exploit the flaw. Vendor fixes are available for the affected builds.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows Server 2012 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows Server 2012 6.x | 6.2.9200.0 – before 6.2.9200.26280 | 6.2.9200.26280 |
| Windows Server 2012 (Server Core installation) 6.x | 6.2.9200.0 – before 6.2.9200.26280 | 6.2.9200.26280 |
| Windows Server 2012 R2 6.x | 6.3.9600.0 – before 6.3.9600.23338 | 6.3.9600.23338 |
| Windows Server 2012 R2 (Server Core installation) 6.x | 6.3.9600.0 – before 6.3.9600.23338 | 6.3.9600.23338 |
| Windows Server 2016 10.x | 10.0.14393.0 – before 10.0.14393.9418 | 10.0.14393.9418 |
| Windows Server 2016 (Server Core installation) 10.x | 10.0.14393.0 – before 10.0.14393.9418 | 10.0.14393.9418 |
| Windows Server 2019 10.x | 10.0.17763.0 – before 10.0.17763.9121 | 10.0.17763.9121 |
| Windows Server 2019 (Server Core installation) 10.x | 10.0.17763.0 – before 10.0.17763.9121 | 10.0.17763.9121 |
| Windows Server 2022 10.x | 10.0.20348.0 – before 10.0.20348.5499 | 10.0.20348.5499 |
| Windows Server 2025 10.x | 10.0.26100.0 – before 10.0.26100.33296 | 10.0.26100.33296 |
Is CVE-2026-62878 being exploited?
Public exploit code is available for CVE-2026-62878.
How to fix CVE-2026-62878
- Apply Microsoft updates that contain the fixes: 6.2.9200.26280, 6.3.9600.23338, 10.0.14393.9418, 10.0.17763.9121, 10.0.20348.5499, or 10.0.26100.33296 as appropriate for your build.
- If immediate patching is not possible, restrict network exposure of DNS servers to trusted networks and block untrusted access at firewalls.
- Follow vendor guidance to verify update installation and restart DNS services or hosts as directed.
- Monitor DNS server logs and network traffic for anomalous queries and signs of exploitation and hunt for indicators of compromise.
Frequently asked questions
Is CVE-2026-62878 being actively exploited?
Public exploit code is available for CVE-2026-62878; there is no CISA Known Exploited Vulnerabilities listing as of 2026-09-29.
Which Windows Server versions are affected by CVE-2026-62878?
The vulnerability affects Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025 builds in the ranges listed by the vendor; consult the affected build ranges to confirm whether your server build is vulnerable.
Is there a patch for CVE-2026-62878?
Yes. Microsoft published updates that fix the issue; apply the fixed builds (for example 6.2.9200.26280, 6.3.9600.23338, 10.0.14393.9418, 10.0.17763.9121, 10.0.20348.5499, 10.0.26100.33296) matching your OS build.
Does CVE-2026-62878 require authentication?
No. The flaw is exploitable without authentication against Windows DNS according to the vendor description.
References
- nvd.nist.gov/vuln/detail/CVE-2026-62878
- cve.org/CVERecord?id=CVE-2026-62878
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62878
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026