Junglewise Threat Intelligence

CVE-2026-69858: Microsoft Windows DNS use-after-free remote code execution

CVE-2026-69858 · Severity: high · CVSS 8.1 · Published 2026-09-08

Executive brief

Windows DNS Server contains a use-after-free vulnerability that allows an unauthenticated attacker to execute arbitrary code remotely over the network. Successful exploitation could compromise DNS infrastructure, enabling attackers to redirect network traffic, intercept communications, or establish persistent footholds in corporate environments that rely on DNS services for critical operations.

Technical details

A use-after-free vulnerability exists in the Windows DNS Server component, where freed memory is accessed after deallocation, potentially allowing arbitrary code execution. The vulnerability is remotely exploitable over the network without requiring authentication or user interaction. An unauthenticated attacker can send specially crafted DNS protocol packets to trigger the flaw and execute code with DNS Server privileges. No public exploits are currently known to be in active use, though the high CVSS score (8.1) reflects the severity of the exposure.

Affected products

  • Microsoft Windows DNS Server

Timeline

  • 2026-09-08: disclosed

References

Related threats