Build1 publisher2 min readPublished
Windows DNS Server's 9.8 bug takes one unauthenticated packet to port 53
Microsoft patched CVE-2026-69730, a CVSS 9.8 remote code execution flaw in the Windows DNS Server role reachable with one unauthenticated packet to port 53. In most Active Directory shops that role runs on the domain controller, so the box answering on port 53 also holds the identity database.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Microsoft's September Patch Tuesday shipped roughly 970 new CVEs, which the writeup describes as a record-setting pile.
- Two of the CVEs in that release are already under active exploitation.
- Zero Day Initiative's Dustin Childs described the flaw as creating 'severe, self-propagating contagion risk across enterprise networks.'
- There is no public proof-of-concept exploit and no CISA KEV listing, and Microsoft rates exploitation 'More Likely.'
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- capability The DNS service runs as SYSTEM, so an exploit that reaches control flow lands as Domain Admin on the host.
- exposure DNS exists to answer unauthenticated strangers, so the 'no credentials' precondition is satisfied by design.
- decision The month's two exploited flaws both need a local foothold first; this one needs only a network path, so patch order cannot simply track where exploitation is already confirmed.
- constraint CVE-2026-72987 is labeled 'Windows DNS' while its sibling fixes say 'Windows DNS Server,' so confirming which component it touches is extra scoping work before treating it as server-only.
CVE-2026-69730 is a use-after-free, bug class CWE-416 [17]. The shape is small. The DNS service allocates a buffer for a parsed name, reads attacker-controlled packet bytes into it, frees the buffer, then keeps using the old pointer after the allocator has handed that slot to something else; if the freed data flows into a function pointer or a vtable, the crash becomes control flow [18].
Zero Day Initiative called the flaw "SigRed's spiritual successor" [5]. SigRed was the 2020 Windows DNS bug that let researchers go from a single DNS query to Domain Admin [6]. Tracked as CVE-2020-1350, it was a crafted SIG record response that expanded past 64KB and overflowed dns.exe, and Check Point reached Domain Admin through the DNS service's own LDAP call [21]. Both bugs sit near DNS name compression. Compression lets a response point back into earlier parts of a packet instead of repeating the name. Parsers chase those offsets with bounded checks, and 25 years of DNS CVEs show how easily that goes wrong [20]. Whether the 2026 bug lives in that compression path is not public [22].
DNS fills six of the release's remote code execution fixes, and ZDI counted 20 wormable-class patches across the whole batch [7][8]. Public detail is thin. Microsoft's description runs a single sentence, and NVD still shows "Awaiting Analysis" [16].
The dev.to writeup that dissected the advisory ranks CVE-2026-69730 the first CVE to patch, and the fix comes down to build numbers [24]. NVD lists the patched builds as 10.0.26100.33438 for Server 2025, 10.0.20348.5622 for Server 2022, and 10.0.17763.9245 for Server 2019 [23]. CVE-2026-69631, an integer-overflow denial of service in Windows DNS rated 7.5 and flagged automatable, shipped in the same 48-hour DNS feed, so a DNS box has more than one fix to validate [9].
What to watch
- A public proof of concept or a CISA KEV listing would move this from Microsoft's 'More Likely' prediction to confirmed exploitation.
- NVD completing its analysis would show whether the bug sits in the name-compression path that SigRed abused, or somewhere else in the parser.
- Clarification of whether CVE-2026-72987's 'Windows DNS' label points at a client or a server component.