CVE-2026-65789 – Windows DNS Server Remote Code Execution Vulnerability

CVSS 8.1 IMPORTANT 2 Critical – Same Day Deployment

“A specially crafted network packet can potentially turn a vulnerable DNS service into a remote code execution path, with no authentication or user interaction required.”

CVE-2026-65789 is a remote code execution vulnerability in Windows DNS caused by a use-after-free condition. An unauthenticated attacker could send a specially crafted packet to an affected DNS service over the network and potentially execute code on the target system. Exploitation requires specific network configurations and timing conditions, making successful exploitation less reliable across all environments.

Key Details

Affected Product
Microsoft Windows 10 1607
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
CWE Classification
CWE-416
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.