CVE-2026-69730: CVSS 9.8 RCE in Windows DNS Server in September Patch
Microsoft's September Patch Tuesday shipped roughly 970 new CVEs, including CVE-2026-69730, a CVSS 9.8 remote code execution flaw in the Windows DNS Server role. It needs no authentication or user interaction — a single crafted packet to port 53 is enough. ZDI called it "SigRed's spiritual successor".
- CVSS 9.8, CWE-416 use-after-free, no auth or user interaction required
- Six DNS RCE fixes in the release, plus an automatable 7.5 DoS
- Fixed builds: Server 2022 at 10.0.20348.5622, Server 2019 at 10.0.17763.9245
- No public PoC or KEV entry; Microsoft rates exploitation "More Likely"
Read next
Security