Junglewise Threat Intelligence

CVE-2026-77886: Microsoft Windows DHCP Server out-of-bounds read

CVE-2026-77886 · Severity: high · CVSS 7.5 · Published 2026-09-08

Executive brief

Windows DHCP Server, a core component that assigns IP addresses to network devices, contains an out-of-bounds memory read vulnerability. An attacker on the network can exploit this flaw to crash the DHCP service, preventing devices from obtaining network connectivity and disrupting normal business operations.

Technical details

An out-of-bounds read vulnerability exists in the Windows DHCP Server service, which handles Dynamic Host Configuration Protocol requests from network clients. The vulnerability allows an unauthenticated attacker on the network to send specially crafted DHCP packets that trigger an out-of-bounds memory read. This causes the DHCP Server service to crash, resulting in a denial of service (DoS) condition where legitimate clients cannot obtain IP address assignments. No code execution or data exfiltration is possible through this vulnerability. A patch is available from Microsoft.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats