CVE-2026-69845 – Windows DHCP Server Remote Code Execution Vulnerability
CVSS 9.8
CRITICAL
Critical - Same Day Deployment
“A specially crafted network request could turn a DHCP server into a path for remote code execution, with no privileges or user action required.”
CVE-2026-69845 is a Critical remote code execution vulnerability in Windows DHCP Server caused by improper input validation leading to a heap-based buffer overflow. An unauthorized in-network attacker could exploit the flaw by calling arbitrary endpoints and potentially execute code remotely. The vulnerability has a CVSS base score of 9.8. It is not publicly disclosed and is not known to be exploited.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-20
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.