Microsoft Windows Server DHCP: 25 Vulnerabilities Disclosed, Two Exploited in the Wild
Microsoft disclosed 25 vulnerabilities in its Windows Server DHCP service on September 8, 2026, including critical flaws and two actively exploited zero-days.

Key findings
- Microsoft patched 25 vulnerabilities in Windows Server DHCP service on September 8, 2026.
- Critical flaws include use-after-free (CVE-2026-72979) and heap-based buffer overflow (CVE-2026-69845) allowing remote code execution.
- Two vulnerabilities (CVE-2026-69845, CVE-2026-72979) were actively exploited in the wild before patching.
- Flaws include out-of-bounds reads, type confusion, and memory management issues, leading to DoS, info disclosure, and RCE.
- All 25 vulnerabilities were fixed in the September 2026 security update; prompt patching is advised.
On September 8, 2026, Microsoft released a significant security update addressing 25 vulnerabilities in the Windows Server DHCP service. This batch of disclosures, all published on the same day, includes a critical vulnerability rated at CVSSv3 9.8 and several high-severity flaws, primarily involving out-of-bounds reads, type confusion, and use-after-free errors. The vulnerabilities could allow unauthorized attackers to cause denial of service, disclose information, or even execute code remotely over a network.
The disclosed vulnerabilities can be broadly categorized by their impact and the underlying vulnerability type. A critical use-after-free vulnerability, CVE-2026-72979, allows for remote code execution. Similarly, critical heap-based buffer overflow vulnerabilities, such as CVE-2026-69845, also permit remote code execution.
Several high-severity vulnerabilities, including CVE-2026-69876 and CVE-2026-69847, are heap-based buffer overflows that enable authorized attackers to execute code over an adjacent network. Other high-severity flaws, like CVE-2026-77895, CVE-2026-77893, CVE-2026-77890, CVE-2026-77889, CVE-2026-77888, CVE-2026-77886, CVE-2026-77502, CVE-2026-77501, CVE-2026-77499, CVE-2026-77498, CVE-2026-77494, and CVE-2026-77895, are related to out-of-bounds reads or type confusion, leading to denial of service. Additionally, CVE-2026-70065 is a high-severity vulnerability due to missing memory release, also resulting in denial of service.
Medium-severity vulnerabilities, such as CVE-2026-77891 and CVE-2026-77887, are out-of-bounds reads that could allow authorized attackers to execute code locally. Other medium-severity flaws, including CVE-2026-70124, CVE-2026-69930, CVE-2026-69929, and CVE-2026-69803, are out-of-bounds reads that enable unauthorized attackers to disclose information. CVE-2026-69878 is a heap-based buffer overflow allowing local code execution. Finally, CVE-2026-69679 and CVE-2026-69637 are medium-severity out-of-bounds reads leading to denial of service over an adjacent network.
Microsoft has acknowledged that two of these vulnerabilities, CVE-2026-69845 and CVE-2026-72979, were actively exploited in the wild prior to their patch release. This exploitation was noted by multiple security researchers, including CrowdStrike and The Hacker News. The sheer volume of vulnerabilities patched by Microsoft in September 2026, totaling 974 across all products, highlights the ongoing challenges in securing complex software ecosystems.
All 25 vulnerabilities affecting the Windows Server DHCP service were addressed in Microsoft's September 2026 security update. Users are strongly advised to apply these updates as soon as possible to mitigate the risks associated with these flaws. Specific version information for affected and patched software is typically detailed in Microsoft's official security advisories, which should be consulted for precise remediation steps.
The coordinated disclosure of these numerous DHCP service vulnerabilities underscores the critical role this service plays in network infrastructure and the potential impact of its compromise. Organizations relying on Windows Server should prioritize patching to protect against potential denial-of-service attacks and unauthorized code execution. The ongoing discovery of such a large batch of related vulnerabilities suggests a need for continuous vigilance and prompt security updates.
This batch of vulnerabilities is significant due to the concentration of critical and high-severity flaws within a single, essential network service. The fact that two of these, CVE-2026-69845 and CVE-2026-72979, were already exploited in the wild adds a layer of urgency for immediate patching. Administrators must ensure their Windows Server DHCP services are updated to prevent potential network disruptions and security breaches.
The vulnerabilities include:
- Out-of-bounds read: CVE-2026-77895, CVE-2026-77893, CVE-2026-77891, CVE-2026-77887, CVE-2026-77502, CVE-2026-77501, CVE-2026-77498, CVE-2026-70124, CVE-2026-69930, CVE-2026-69929, CVE-2026-69803, CVE-2026-69679, CVE-2026-69637.
- Type confusion: CVE-2026-77890, CVE-2026-77889, CVE-2026-77888, CVE-2026-77499, CVE-2026-77494.
- Use after free: CVE-2026-72979, CVE-2026-69876.
- Heap-based buffer overflow: CVE-2026-69878, CVE-2026-69847, CVE-2026-69845.
- Missing release of memory: CVE-2026-70065.
The coordinated disclosure of these 25 vulnerabilities in the Windows Server DHCP service on September 8, 2026, highlights a critical security event for Microsoft infrastructure. The batch includes a critical use-after-free flaw and numerous high-severity issues, with two vulnerabilities already being exploited in the wild.
Key findings from this disclosure include the presence of a critical use-after-free vulnerability (CVE-2026-72979) and a critical heap-based buffer overflow (CVE-2026-69845), both allowing for remote code execution. Multiple high-severity out-of-bounds read and type confusion vulnerabilities were also disclosed, primarily leading to denial-of-service conditions. The active exploitation of CVE-2026-69845 and CVE-2026-72979 prior to patching underscores the immediate threat posed by these flaws.
Microsoft addressed all 25 vulnerabilities in its September 2026 security update, and users are urged to apply these patches promptly. The sheer volume of vulnerabilities patched in this single event, alongside other Microsoft products, indicates a broad security challenge that requires diligent system administration and timely updates.
This batch of vulnerabilities is particularly concerning due to the essential nature of the DHCP service and the severity of the disclosed flaws, including remote code execution capabilities. The fact that two of these vulnerabilities were actively exploited in the wild adds significant urgency for organizations to apply the available patches.
The vulnerabilities disclosed include:
- Critical Use-after-free (CVE-2026-72979) and Heap-based buffer overflow (CVE-2026-69845) allowing remote code execution.
- Multiple High-severity Out-of-bounds reads and Type confusion flaws leading to Denial of Service.
- Medium-severity vulnerabilities enabling local code execution, information disclosure, and denial of service.
- Two vulnerabilities (CVE-2026-69845, CVE-2026-72979) were exploited in the wild before patching.
- All 25 vulnerabilities were fixed in Microsoft's September 2026 security update.
A stylized representation of a Windows Server DHCP service icon, with network packets flowing into it, and some packets are corrupted or dissolving into digital static, symbolizing the denial-of-service and code execution vulnerabilities. The background is a dark network grid.