• PATCH AVAILABLE

CVE-2026-72979: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An unauthenticated attacker can execute arbitrary code against the Windows DHCP Server component, enabling full system compromise (CVE-2026-72979). The flaw is a use-after-free (CWE-416) in DHCP Server and affects multiple Microsoft branches: Windows 10 Version 1607 and 1809, Windows Server 2012 and 2012 R2, Windows Server 2016 and 2019 within the build ranges listed by the vendor. An attacker only needs network access to the DHCP Server service; no credentials or user interaction are required.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-416
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Apply vendor updates immediately: this is a network-accessible, unauthenticated remote code execution flaw and a fixed build is published for each affected branch. Treat systems exposed to untrusted networks as highest priority.

What is CVE-2026-72979?

An unauthenticated attacker can execute arbitrary code against the Windows DHCP Server component, enabling full system compromise (CVE-2026-72979). The flaw is a use-after-free (CWE-416) in DHCP Server and affects multiple Microsoft branches: Windows 10 Version 1607 and 1809, Windows Server 2012 and 2012 R2, Windows Server 2016 and 2019 within the build ranges listed by the vendor. An attacker only needs network access to the DHCP Server service; no credentials or user interaction are required. The weakness is classified as CWE-416 (Use After Free).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349
Windows Server 2012 (Server Core installation) 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349
Windows Server 2012 R2 6.x6.3.9600.0 – before 6.3.9600.233986.3.9600.23398
Windows Server 2012 R2 (Server Core installation) 6.x6.3.9600.0 – before 6.3.9600.233986.3.9600.23398
Windows Server 2016 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows Server 2016 (Server Core installation) 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows Server 2019 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows Server 2019 (Server Core installation) 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245

Is CVE-2026-72979 being exploited?

There are no public reports of active exploitation as of 2026-09-29.

How to fix CVE-2026-72979

  1. Install the Microsoft updates that include the fixed builds: 10.0.14393.9512 for Windows 10 Version 1607 / Server 2016, 10.0.17763.9245 for Windows 10 Version 1809 / Server 2019, 6.2.9200.26349 for Windows Server 2012, and 6.3.9600.23398 for Windows Server 2012 R2.
  2. If you cannot patch immediately, restrict network exposure to DHCP Server (block access from untrusted networks and use network segmentation).
  3. Monitor DHCP Server logs and system event logs for unusual activity and signs of exploitation, and review IDS/IPS alerts for suspicious DHCP traffic.
  4. Follow Microsoft guidance for post-patch verification and roll back only if necessary after testing updates in a controlled environment.

Frequently asked questions

Is CVE-2026-72979 being actively exploited?

There are no public reports of active exploitation of CVE-2026-72979 as of 2026-09-29.

Which Windows versions are affected by CVE-2026-72979?

The DHCP Server use-after-free affects Windows 10 Version 1607 and 1809 and Windows Server 2012, 2012 R2, 2016 and 2019 within the build ranges published by Microsoft.

Is there a patch for CVE-2026-72979?

Yes. Microsoft published fixed builds: 10.0.14393.9512, 10.0.17763.9245, 6.2.9200.26349, and 6.3.9600.23398 for the affected branches.

Does CVE-2026-72979 require authentication?

No. The vulnerability can be exploited without authentication; an attacker only needs network access to the DHCP Server service.

References