Junglewise Threat Intelligence

CVE-2026-69680: Microsoft Windows DNS origin validation bypass

CVE-2026-69680 · Severity: high · CVSS 8.1 · Published 2026-09-08

Technologies: Microsoft Windows DNS Server. Vendors: Microsoft.

Executive brief

Windows DNS Server is vulnerable to a validation error that allows attackers to forge DNS responses and redirect network traffic to malicious servers. An attacker can intercept DNS queries and inject spoofed responses to compromise the integrity of name resolution, potentially redirecting users to phishing sites or malware distribution points without authentication.

Technical details

This vulnerability is an origin validation error in Windows DNS Server that fails to properly validate the source of DNS responses. The flaw allows network-based attackers to perform DNS spoofing attacks by crafting malicious DNS responses that bypass origin authentication checks. An attacker positioned on the network can intercept and respond to DNS queries faster than legitimate DNS servers, or exploit timing windows to inject spoofed responses. This enables redirection of traffic to attacker-controlled servers, potentially facilitating phishing, malware distribution, or man-in-the-middle attacks. Microsoft has released security updates to address this validation bypass.

Affected products

  • Microsoft Windows DNS Server <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats