Microsoft Windows DNS: 16 Vulnerabilities Disclosed Together, Ranging to Critical Remote Code Execution
Microsoft disclosed 16 Windows DNS vulnerabilities on August 11, 2026, including critical flaws allowing remote code execution.

Key findings
- 16 Windows DNS vulnerabilities disclosed together on August 11, 2026.
- Flaws include heap overflows, integer overflows, use-after-free, and race conditions.
- Vulnerabilities range from local privilege escalation to remote code execution.
- Critical flaw CVE-2026-62878 allows network-based code execution.
- Microsoft released patches as part of the August 2026 Patch Tuesday.
Microsoft released a significant batch of 16 vulnerabilities affecting Windows DNS on August 11, 2026. The disclosures, all occurring within a two-minute window, highlight a range of issues including heap-based buffer overflows, integer overflows, numeric truncation errors, use-after-free flaws, and race conditions. While most of these vulnerabilities allow for local privilege escalation, several critical and high-severity flaws enable unauthorized attackers to execute code remotely or over an adjacent network.
The vulnerabilities can be broadly categorized by their impact and the underlying bug class:
- Privilege Escalation (Local): A majority of the disclosed CVEs, including CVE-2026-70330, CVE-2026-70304, CVE-2026-65799, CVE-2026-65798, CVE-2026-65797, CVE-2026-65795, CVE-2026-62883, CVE-2026-62881, and CVE-2026-62769, are related to heap-based buffer overflows, integer overflows, numeric truncation errors, or unspecified issues within Windows DNS. These vulnerabilities require local authorization but allow an attacker to elevate privileges.
- Remote Code Execution (Network): Several high and critical severity vulnerabilities pose a greater threat, allowing for code execution without requiring local access. CVE-2026-62878, a stack-based buffer overflow, is rated Critical (CVSSv3 9.8) and allows for network-based code execution. High-severity flaws like CVE-2026-65789 (Use after free), CVE-2026-62817 (Out-of-bounds write), CVE-2026-62787 (Use after free), and CVE-2026-62778 (Use after free) also permit attackers to execute code over a network or adjacent network. CVE-2026-62820, a race condition vulnerability, and CVE-2026-61920, another race condition, also fall into this category, allowing for remote code execution.
- Race Conditions: CVE-2026-62820 and CVE-2026-61920 involve race conditions in Windows DNS, enabling unauthorized attackers to execute code over a network.
Microsoft's August 2026 Patch Tuesday addressed these vulnerabilities, with fixes being released on August 11, 2026. The vendor has not explicitly detailed specific version numbers for all affected systems, but the patching indicates that all vulnerable versions have been addressed. Users are strongly advised to apply these security updates promptly to mitigate the risks associated with these vulnerabilities.
The simultaneous disclosure of these 16 vulnerabilities underscores the importance of timely patching for critical infrastructure components like Windows DNS. The presence of critical and high-severity flaws that allow for remote code execution necessitates immediate attention from system administrators to prevent potential exploitation by malicious actors.
The related news coverage highlights that while this batch focuses on Windows DNS, Microsoft's August 2026 Patch Tuesday also included fixes for a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (AFD.sys), which was reportedly exploited in the wild by North Korean attackers. This broader context emphasizes the ongoing threat landscape and the critical need for organizations to stay vigilant and apply all available security updates.
This batch of vulnerabilities, affecting Windows DNS, presents a significant risk due to the potential for privilege escalation and remote code execution. Prompt application of Microsoft's August 2026 security updates is crucial for all organizations running affected Windows systems.
CVE-2026-70330, CVE-2026-70304, CVE-2026-65799, CVE-2026-65798, CVE-2026-65797, CVE-2026-65795, CVE-2026-65789, CVE-2026-62883, CVE-2026-62881, CVE-2026-62878, CVE-2026-62820, CVE-2026-62817, CVE-2026-62787, CVE-2026-62778, CVE-2026-62769, CVE-2026-61920