CVE-2026-69858CriticalCVSS 8.1
Windows DNS Server Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
🎯 Affected products4
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
- Windows Server 2025
- Windows Server 2025 (Server Core installation)
✅ Remediation
KB5122882 (Security Update) — fixed build 10.0.20348.5622 KB5122871 (Security Update) — fixed build 10.0.26100.33438
🔗 References (5)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69858
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5122882
- referencehttps://support.microsoft.com/help/5122882
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5122871
- referencehttps://support.microsoft.com/help/5122871