CVE-2026-62878

Published Aug 11, 2026

Last updated 3 days ago

Overview

Description
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_10_1607, windows_10_1809, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2025

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

secure@microsoft.com
CWE-121

Social media

Hype score
Not currently trending
  1. New critical RCEs in MS QUIC (CVE-2026-62815) & Windows DNS (CVE-2026-62878) demand urgent patching to protect data. Also, MLflow SSRF (CVE-2026-64849) exposes internal services. Act now! #Cybersecurity #Vulnerabilities #NetSec

    @YourAnon_irc

    20 Aug 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. New critical RCEs: MS QUIC (CVE-2026-62815), Kemp LoadMaster (CVE-2026-8037), S2OPC (Aug 18), & Win DNS (CVE-2026-62878) threaten data privacy/integrity in transit. Patch NOW! #Cybersecurity #Vulnerabilities #InfoSec

    @YourAnon_irc

    19 Aug 2026

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 August 19, 2026 Patch Advisories Today's advisories target these CVEs; - Microsoft Defender ShieldBreak (CVE-2026-69414) - SharePoint full RCE chain (CVE-2026-55040 and CVE-2026-63520 - Windows DNS Server (CVE-2026-62878, CVSS 9.8) https://t.co/fR71dyoG2H | #CyberSafeUG h

    @CERT_UG

    19 Aug 2026

    151 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🔥 CyberForge CVE of the Day #028 🚨 CVE-2026-62878 — Microsoft has patched a Critical unauthenticated RCE in Windows DNS Server. A remote attacker could exploit a stack-based buffer overflow over the network—no credentials or user interaction required. Microsoft describ

    @lee1981b

    19 Aug 2026

    122 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 【技術解説】「無操作でワーム化」— 8月のパッチ最優先はDNSサーバRCEだ 8月Patch Tuesdayは421 CVE超。中でもCVE-2026-62878はWindows DNS

    @iss_kk_official

    16 Aug 2026

    117 Impressions

    2 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 August 13 Patch Advisories Cisco ASA and FTD (CVE-2026-20349): actively exploited, no patch yet. One request crashes your VPN gateway. Windows DNS Server (CVE-2026-62878, CVSS 9.8): unauthenticated RCE, no credentials needed. Windows Container Driver (CVE-2026-72971). h

    @CERT_UG

    13 Aug 2026

    231 Impressions

    2 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨Critical - Windows DNS Server Unauthenticated Remote Code Execution (CVE-2026-62878) A stack-based buffer overflow in the Windows DNS Server role lets an unauthorized attacker execute code over the network, with no privileges and no user interaction required. Impact is full

    @UpwindMDR

    12 Aug 2026

    80 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 Microsoft August Patch Tuesday — 398+ CVEs, 3 Zero-Days CVE-2026-68820 — WinSock EoP (ACTIVE zero-day, Lazarus) CVE-2026-62878 — DNS Server RCE (9.8, wormable) CVE-2026-62893 — TFTP Server RCE (9.8, more likely) → https://t.co/vOC4TItXgB #cybersecurity #PatchTuesd

    @ThreatAft

    12 Aug 2026

    84 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.