chiprook
← Security
SecurityOctober 4, 2026, 09:14

CVE-2026-69730: CVSS 9.8 RCE in Windows DNS Server in September Patch

Microsoft's September Patch Tuesday shipped roughly 970 new CVEs, including CVE-2026-69730, a CVSS 9.8 remote code execution flaw in the Windows DNS Server role. It needs no authentication or user interaction — a single crafted packet to port 53 is enough. ZDI called it "SigRed's spiritual successor".

CVE-2026-69730: CVSS 9.8 RCE in Windows DNS Server in September Patch
#Microsoft#Windows
Read next
Security

LightLLM hit by two CVSS 9.8 unauthenticated RCE flaws

Security

F5 patches exploited CVSS 9.8 flaw in BIG-IP APM

Security

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Security

Four WordPress plugins hit by CVSS 9.8 auth bypass flaws