• PATCH AVAILABLE

CVE-2026-69730: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An unauthenticated attacker can execute arbitrary code on Windows systems via a use-after-free flaw in the DNS component, tracked as CVE-2026-69730. Affected builds include Windows 10 Version 1607 (10.0.14393.0 up to before 10.0.14393.9512), Windows 10 Version 1809 (10.0.17763.0 up to before 10.0.17763.9245), and matching Windows Server 2012/2012 R2/2016/2019 branches with the listed build ranges. Exploitation requires network access to the vulnerable DNS service and does not require valid credentials or user interaction.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-416
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a pre-auth remote code execution vulnerability that allows unauthenticated code execution over the network, so prioritize installing the vendor fixes immediately to prevent remote compromise.

What is CVE-2026-69730?

An unauthenticated attacker can execute arbitrary code on Windows systems via a use-after-free flaw in the DNS component, tracked as CVE-2026-69730. Affected builds include Windows 10 Version 1607 (10.0.14393.0 up to before 10.0.14393.9512), Windows 10 Version 1809 (10.0.17763.0 up to before 10.0.17763.9245), and matching Windows Server 2012/2012 R2/2016/2019 branches with the listed build ranges. Exploitation requires network access to the vulnerable DNS service and does not require valid credentials or user interaction. The weakness is classified as CWE-416 (Use After Free).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349
Windows Server 2012 (Server Core installation) 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349
Windows Server 2012 R2 6.x6.3.9600.0 – before 6.3.9600.233986.3.9600.23398
Windows Server 2012 R2 (Server Core installation) 6.x6.3.9600.0 – before 6.3.9600.233986.3.9600.23398
Windows Server 2016 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows Server 2016 (Server Core installation) 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows Server 2019 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows Server 2019 (Server Core installation) 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245

Is CVE-2026-69730 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-69730

  1. Install the vendor updates that include the fixes: 10.0.14393.9512 for Windows 10 Version 1607/Server 2016, 10.0.17763.9245 for Windows 10 Version 1809/Server 2019, and the listed server fixes (6.2.9200.26349, 6.3.9600.23398) for Server 2012/2012 R2.
  2. Apply the updates promptly to internet-facing and internal systems running the affected builds.
  3. If immediate patching is not possible, restrict network exposure to the DNS service and monitor for unusual DNS-related activity.
  4. Follow Microsoft guidance and verify successful installation of the fixed builds on impacted hosts.

Frequently asked questions

Is CVE-2026-69730 being actively exploited?

There are no public reports of exploitation of CVE-2026-69730 as of 2026-09-29.

Which Windows 10 Version 1607 versions are affected by CVE-2026-69730?

Windows 10 Version 1607 builds from 10.0.14393.0 up to but not including 10.0.14393.9512 are affected; related Windows 10/Server branches and build ranges listed by the vendor are also affected.

Is there a patch for CVE-2026-69730?

Yes. Microsoft published fixes; affected builds are fixed at 10.0.14393.9512, 10.0.17763.9245, 6.2.9200.26349, and 6.3.9600.23398 according to the vendor.

Does CVE-2026-69730 require authentication?

No. The vulnerability in the Windows DNS component can be exploited without authentication and without user interaction.

References