CVE-2026-72928: Windows DNS Server Remote Code Execution Vulnerability
Published Sep 8, 2026
·Updated
Use after free in Windows DNS allows an authorized attacker to execute code over a network.
Other sources
Windows DNS Server Remote Code Execution Vulnerability
— Microsoft
Affected Software
2 affected componentsFixes available
Microsoft Windows Server 2025<10.0.26100.33438
10.0.26100.33438
Microsoft Windows Server 2025<10.0.26100.33438
10.0.26100.33438
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.33438Patch KB5122871
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Affected Software
CVE Published
via MITRE·05:17 PM
Data Sourced
via MITRE·05:17 PM
DescriptionSeverity
Frequently Asked Questions
1
What level of access does an attacker need?
The vector indicates network access is required, with low privileges and no user interaction. Exploitation is rated high complexity.
2
What is the potential impact if exploitation succeeds?
The provided metrics rate confidentiality, integrity, and availability impact as high. Successful exploitation could therefore affect all three security properties.
3
Which systems are identified as affected?
The provided data identifies Microsoft Windows Server 2025. It does not provide affected build numbers, patch levels, or configuration-specific scope.