FR
live
Networking Critical CVSS 9.8

Microsoft patches a wormable Windows DNS Server RCE, six years after SigRed

September 2026’s Patch Tuesday, the largest in Microsoft’s history, closes a wormable RCE in Windows DNS Server, the first SigRed-class flaw since 2020. Isolate and patch your exposed DNS, DHCP and multicast servers first.

The face of a dark patch panel with identical grey network ports, one empty socket glowing amber where its cable was pulled out.

September 8, 2026. Microsoft ships the largest Patch Tuesday in its history, fixing 974 CVEs. September 8, 2026. Two zero-days already exploited in the wild are closed: CVE-2026-85880, a heap overflow in Windows ALPC, and CVE-2026-81963, a link-following flaw in the Windows Update stack. September 8, 2026. Among the 20 flaws rated wormable is CVE-2026-69730, a remote code execution in Windows DNS Server that Dustin Childs of the Zero Day Initiative calls the spiritual successor to SigRed. Why it matters: a wormable RCE in a DNS service running as SYSTEM is the most dangerous self-propagating scenario since CVE-2020-1350, and it arrives in a batch that concentrates network flaws.

A use-after-free in the heart of Windows DNS

CVE-2026-69730 is classified CWE-416, use-after-free. In practice, a specially crafted DNS request pushes the server process into reusing a memory region that has already been freed. Picture it this way: the server keeps a pointer to a request buffer, frees that buffer at the end of one operation, then — because of a race condition in processing the next request — writes into the buffer it just freed. An attacker who controls the request content controls what gets written, and therefore the execution flow.

The vector is the worst possible for a network service: AV:N/AC:L/PR:N/UI:N — reachable over the network, low attack complexity, no privileges required, no user interaction. The CVSS 9.8 score reflects that combination, and the result runs with the DNS service’s privileges — on Windows, the SYSTEM account. The reach is broad: Windows Server 2012 through 2025, in both standard and Server Core installations, plus Windows 10 1607 and 1809.

SigRed, the precedent everyone compares against

SigRed (CVE-2020-1350) remains the reference point. In July 2020, Check Point revealed a wormable RCE in Windows DNS Server, triggered by a single malformed DNS query — rated CVSS 10.0, the absolute maximum. The flaw had slept in the code for 17 years. Microsoft had to ship an out-of-band emergency patch, and CISA issued a federal directive for immediate application, so real was the worm risk.

The comparison with CVE-2026-69730 is doubly instructive. The mechanism differs — use-after-free versus an integer overflow — but the class is identical: a bug exploitable by a single network packet, in a service running as SYSTEM. The difference this time is that the flaw is fixed in the ordinary monthly cycle, with no emergency alert — which does nothing to reduce the urgency for estates that have not applied the patch yet.

Twenty wormable flaws, a batch concentrated at the network layer

The DNS RCE is not isolated. According to Dustin Childs, 20 of the batch’s vulnerabilities are wormable — exploitable for remote code execution without authentication or interaction. Several hit network services that a Windows estate exposes by default.

  • DHCP Server. A critical RCE, rated 9.8, in the address-assignment service — another component enterprise fleets expose without thinking about it.
  • RMCAST. CVE-2026-69530, an RCE in the reliable multicast protocol, also rated 9.8.
  • IP Helper. CVE-2026-72981, an RCE in the network assistance service, rated 9.8.

On top of those sit critical RCEs in Hyper-V, Remote Desktop Services, SQL Server, Exchange Server and SharePoint. The batch’s shape is telling: the most dangerous flaws are not in business applications but in the network plumbing and infrastructure services nobody bothers to map.

The two zero-days already exploited

The batch also carries two locally exploited privilege escalations, both listed in CISA’s KEV catalog with a federal deadline of September 22, 2026.

  • CVE-2026-85880 — a heap overflow in Windows ALPC that lets an attacker already present, even inside a low-privilege AppContainer, escalate to SYSTEM.
  • CVE-2026-81963 — a link-following flaw in the Windows Update stack, the first zero-day weakness in that component in five years.

Both require prior code execution — a phished endpoint, stolen credentials, lateral movement. But combined with the wormable DNS RCE, they sketch a full chain: initial compromise through a network service, then local escalation to total control.

What segmentation buys before the patch

When the patch cannot be applied immediately, defense moves to topology. A DNS server that only resolves for internal clients has no business being reachable from the internet: taking it out of public exposure, placing it in a dedicated subnet, and allowing only ports 53/TCP and 53/UDP from legitimate segments dramatically shrinks the surface.

  • Disable recursion where it is not needed. A server that is only authoritative for its zones has no reason to accept arbitrary recursive queries.
  • Log abnormal queries. A burst of malformed requests on port 53 is the first sign of an exploitation attempt, long before a worm spreads.

None of this replaces the patch, but it converts an exploitable-by-default posture into one where an attacker must first locate a reachable, recursive resolver — a far smaller target, and the first thing to remove from the public internet.

A record volume that changes prioritization

The 974-CVE figure is itself a signal. Microsoft attributes the growth to its AI-assisted vulnerability discovery system, which produces larger patch sets than a human team could assemble.

The consequence for a CISO is not “patch everything” — with nearly 1,000 fixes a month, that is impossible to absorb overnight. It is risk-based prioritization: exploited zero-days first, then wormable network services, then internet-facing applications. The first-three-hours rule is not negotiable for CVE-2026-69730 on an exposed DNS server.

Before patching, the first question is exposure: how many of these services are actually reachable. A Windows DNS Server inside a flat network is reachable by every workstation — which is why the practical first step is not the patch itself but the inventory. Scan for port 53, 67/68 (DHCP) and the RMCAST service, then compare the result against what your asset register says. The gap between the two is where a wormable RCE becomes a wormable outbreak.

The common thread across the batch is that DNS is a crown-jewel service. It is the first link in almost every connection — name resolution, service discovery, and in some Active Directory configurations, authentication itself. An attacker who controls a domain’s DNS server controls the map of the network and can silently redirect internal traffic, which is why a SYSTEM-level RCE here should be treated as a potential domain compromise rather than a routine monthly patch.

Verdict

If you run Windows DNS Server, apply the September patch first on servers that resolve for clients or are reachable from untrusted segments: it is the only defense against a wormable RCE running as SYSTEM. If you manage a Windows infrastructure estate, inventory your DHCP, RMCAST and IP Helper servers — they are often missing from the priority-patch list while carrying 9.8 RCEs. And if you cannot patch immediately, segment DNS and DHCP behind restrictive firewall rules and disable recursion where it is not needed: that is the time the remediation effort buys.

References

cve

Linked vulnerabilities

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

The official MCP Python SDK lets a malicious server steal OAuth credentials

A flaw in the official Python SDK of the MCP protocol lets a malicious server redirect the client secret, the authorization code, and the PKCE proof key to a token endpoint it controls. Upgrade to 1.30.0 or 2.2.0, set the issuer parameter, and rotate your OAuth secrets.

← Back to the feed

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss