- Description
- Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
- Products
- windows_10_1607, windows_10_1809, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2025
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- secure@microsoft.com
- CWE-121
- Hype score
- Not currently trending
New critical RCEs in MS QUIC (CVE-2026-62815) & Windows DNS (CVE-2026-62878) demand urgent patching to protect data. Also, MLflow SSRF (CVE-2026-64849) exposes internal services. Act now! #Cybersecurity #Vulnerabilities #NetSec
@YourAnon_irc
20 Aug 2026
42 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
New critical RCEs: MS QUIC (CVE-2026-62815), Kemp LoadMaster (CVE-2026-8037), S2OPC (Aug 18), & Win DNS (CVE-2026-62878) threaten data privacy/integrity in transit. Patch NOW! #Cybersecurity #Vulnerabilities #InfoSec
@YourAnon_irc
19 Aug 2026
46 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 August 19, 2026 Patch Advisories Today's advisories target these CVEs; - Microsoft Defender ShieldBreak (CVE-2026-69414) - SharePoint full RCE chain (CVE-2026-55040 and CVE-2026-63520 - Windows DNS Server (CVE-2026-62878, CVSS 9.8) https://t.co/fR71dyoG2H | #CyberSafeUG h
@CERT_UG
19 Aug 2026
151 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔥 CyberForge CVE of the Day #028 🚨 CVE-2026-62878 — Microsoft has patched a Critical unauthenticated RCE in Windows DNS Server. A remote attacker could exploit a stack-based buffer overflow over the network—no credentials or user interaction required. Microsoft describ
@lee1981b
19 Aug 2026
122 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
【技術解説】「無操作でワーム化」— 8月のパッチ最優先はDNSサーバRCEだ 8月Patch Tuesdayは421 CVE超。中でもCVE-2026-62878はWindows DNS
@iss_kk_official
16 Aug 2026
117 Impressions
2 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨 August 13 Patch Advisories Cisco ASA and FTD (CVE-2026-20349): actively exploited, no patch yet. One request crashes your VPN gateway. Windows DNS Server (CVE-2026-62878, CVSS 9.8): unauthenticated RCE, no credentials needed. Windows Container Driver (CVE-2026-72971). h
@CERT_UG
13 Aug 2026
231 Impressions
2 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨Critical - Windows DNS Server Unauthenticated Remote Code Execution (CVE-2026-62878) A stack-based buffer overflow in the Windows DNS Server role lets an unauthorized attacker execute code over the network, with no privileges and no user interaction required. Impact is full
@UpwindMDR
12 Aug 2026
80 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Microsoft August Patch Tuesday — 398+ CVEs, 3 Zero-Days CVE-2026-68820 — WinSock EoP (ACTIVE zero-day, Lazarus) CVE-2026-62878 — DNS Server RCE (9.8, wormable) CVE-2026-62893 — TFTP Server RCE (9.8, more likely) → https://t.co/vOC4TItXgB #cybersecurity #PatchTuesd
@ThreatAft
12 Aug 2026
84 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "14FF7EDA-F43B-4BB4-BC6C-7EFE15382EEB",
"versionEndExcluding": "10.0.14393.9418",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "CB3EDBCC-9F4E-49F2-9701-67D2C1F7B47A",
"versionEndExcluding": "10.0.14393.9418",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "EA21CBE0-4C65-47D4-8C92-886825FE5046",
"versionEndExcluding": "10.0.17763.9121",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "A2E88C42-4E6A-42B5-8C12-596103B5BCE1",
"versionEndExcluding": "10.0.17763.9121",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
"matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
"matchCriteriaId": "14EEFCD3-C815-4CBE-99AB-6AFB40EF2FE9",
"versionEndExcluding": "10.0.14393.9418",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E17AFA65-CA49-4B2E-8E34-0443D2060155",
"versionEndExcluding": "10.0.17763.9121",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8EBC7E47-4744-4802-B04C-869AA63985A5",
"versionEndExcluding": "10.0.20348.5440",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
"matchCriteriaId": "48C0EB1A-5EC0-4916-A812-08E16FEB040A",
"versionEndExcluding": "10.0.26100.33222",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]