• PATCH AVAILABLE

CVE-2026-69845: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An unauthenticated attacker can trigger a heap-based buffer overflow in the Windows DHCP Server and execute arbitrary code over the network. CVE-2026-69845 affects multiple Windows branches including Windows 10 Version 1607 and 1809 builds, Windows Server 2012 / 2012 R2, Windows Server 2016 and Windows Server 2019; vendor data lists specific affected builds and corresponding fixed builds. An attacker only needs network access to the DHCP service—no valid credentials or user interaction are required.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.01022
CWE
CWE-122
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this vulnerability allows remote code execution without authentication, so prioritize patching to the fixed builds listed by Microsoft; if immediate patching is impractical, restrict network access to DHCP services and monitor for suspicious activity.

What is CVE-2026-69845?

An unauthenticated attacker can trigger a heap-based buffer overflow in the Windows DHCP Server and execute arbitrary code over the network. CVE-2026-69845 affects multiple Windows branches including Windows 10 Version 1607 and 1809 builds, Windows Server 2012 / 2012 R2, Windows Server 2016 and Windows Server 2019; vendor data lists specific affected builds and corresponding fixed builds. An attacker only needs network access to the DHCP service—no valid credentials or user interaction are required. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349
Windows Server 2012 (Server Core installation) 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349
Windows Server 2012 R2 6.x6.3.9600.0 – before 6.3.9600.233986.3.9600.23398
Windows Server 2012 R2 (Server Core installation) 6.x6.3.9600.0 – before 6.3.9600.233986.3.9600.23398
Windows Server 2016 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows Server 2016 (Server Core installation) 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows Server 2019 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows Server 2019 (Server Core installation) 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245

Is CVE-2026-69845 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-69845

  1. Install the vendor updates that move systems to the fixed builds (for example 10.0.14393.9512 or 10.0.17763.9245 and the corresponding server fixes listed by Microsoft).
  2. If you cannot patch immediately, block or limit network exposure to DHCP services at network boundaries and between untrusted networks.
  3. Monitor DHCP server logs and host telemetry for unexpected crashes, process launches, or suspicious activity and investigate promptly.
  4. Follow Microsoft’s guidance and apply any additional vendor mitigations or workarounds they publish.

Frequently asked questions

Is CVE-2026-69845 being actively exploited?

There are no public reports of active exploitation of CVE-2026-69845 as of 2026-09-29.

Which Windows versions are affected by CVE-2026-69845?

The flaw impacts Windows DHCP Server builds across Windows 10 Version 1607 and 1809, Windows Server 2012 and 2012 R2, Windows Server 2016, and Windows Server 2019 as listed in the vendor's affected builds.

Is there a patch for CVE-2026-69845?

Yes; Microsoft published fixes and lists fixed builds such as 10.0.14393.9512, 10.0.17763.9245 and server build equivalents—apply those updates.

Does CVE-2026-69845 require authentication?

No; the vulnerability can be exploited without authentication given network access to the Windows DHCP Server.

References