Microsoft patches nine Windows DNS Server RCEs, including a CVSS 9.8 use-after-free
The September 8, 2026 Patch Tuesday fixes nine remote code execution flaws in Windows DNS Server, including CVE-2026-69730, a CVSS 9.8 use-after-free triggerable with a single forged packet. Patch the servers running the DNS role first and segment port 53 before a public exploit appears.