CVE-2026-62878Patch(microsoft / windows_10_1607)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_server_2012
  • windows_server_2016

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 27 mentions across 16 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 16 signals
  • Technical details provided in 19 signals
  • Disclosure: 4 classified signals
  • Peaked 14d ago at 4 mentions (2026-08-12); latest day: 3
  • 27 total mentions across 16 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_server_2012windows_server_2016windows_server_2019windows_server_2022windows_server_2025

2 versions affected across 7 products

Deep dive

Activity timeline27 mentions / 16d
01234Mentions · 2026-08-11: 1Mentions · 2026-08-12: 4Mentions · 2026-08-13: 2Mentions · 2026-08-14: 1Mentions · 2026-08-15: 1Mentions · 2026-08-16: 1Mentions · 2026-08-17: 1Mentions · 2026-08-18: 1Mentions · 2026-08-19: 4Mentions · 2026-08-20: 1Mentions · 2026-08-21: 1Mentions · 2026-08-24: 1Mentions · 2026-08-25: 2Mentions · 2026-09-09: 1Mentions · 2026-09-24: 2Mentions · 2026-09-25: 3Active Exploitation · 2026-08-12: 2Active Exploitation · 2026-08-13: 1Patch / Workaround · 2026-08-11: 1Patch / Workaround · 2026-08-12: 2Patch / Workaround · 2026-08-13: 1Patch / Workaround · 2026-08-14: 1Patch / Workaround · 2026-08-16: 1Patch / Workaround · 2026-08-18: 1Patch / Workaround · 2026-08-19: 4Patch / Workaround · 2026-08-20: 1Patch / Workaround · 2026-08-21: 1Patch / Workaround · 2026-08-24: 1Patch / Workaround · 2026-08-25: 2Technical Details · 2026-08-11: 1Technical Details · 2026-08-12: 2Technical Details · 2026-08-13: 2Technical Details · 2026-08-14: 1Technical Details · 2026-08-15: 1Technical Details · 2026-08-17: 1Technical Details · 2026-08-18: 1Technical Details · 2026-08-19: 4Technical Details · 2026-08-20: 1Technical Details · 2026-08-21: 1Technical Details · 2026-08-24: 1Technical Details · 2026-08-25: 2Technical Details · 2026-09-09: 108-1108-1208-1308-1408-1508-1608-1708-1808-1908-2008-2108-2408-2509-0909-2409-25
Signal classification3 categories
Patch
1568.2%
Disclosure
418.2%
Active Exploitation
313.6%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-08-111
Patch1
2026-08-124
Active Exploitation2Patch2
2026-08-132
Active Exploitation1Patch1
2026-08-141
Patch1
2026-08-151
Disclosure1
2026-08-161
Patch1
2026-08-171
Patch1
2026-08-181
Patch1
2026-08-194
Disclosure1Patch3
2026-08-201
Patch1
2026-08-211
Patch1
2026-08-241
Patch1
2026-08-252
Disclosure1Patch1
2026-09-091
Disclosure1
Full discourse20 posts
  • dbugs@ptdbugs

    A PoC/exploit has been discovered for vulnerability CVE-2026-62878 PT ID: PT-2026-70575 Vendor: Microsoft Product: Windows DNS Server Description: A stack-based buffer overflow vulnerability in Windows DNS Server allows an unauthenticated remote attacker to corrupt memory by sending specially crafted DNS queries. Successful exploitation can lead to denial of service and may allow arbitrary code execution in the context of the DNS Server process. Microsoft classifies the vulnerability as a remote code execution vulnerability. References: • https://dbu.gs/vulnerability/PT-2026-70575 • https://github.com/nmlz/CVE-2026-62878

    00033480
    3.6K followersView on X
  • National CERT/CC@CERT_UG
    Active Exploitation

    🚨 August 13 Patch Advisories Cisco ASA and FTD (CVE-2026-20349): actively exploited, no patch yet. One request crashes your VPN gateway. Windows DNS Server (CVE-2026-62878, CVSS 9.8): unauthenticated RCE, no credentials needed. Windows Container Driver (CVE-2026-72971). https://t.co/oVbQUMBJjk

    Post summary

    The tweet warns that CVE‑2026‑20349 (Cisco ASA/FTD) and CVE‑2026‑62878 (Windows DNS) are actively exploited in the wild, with the former causing VPN gateway crashes and the latter enabling unauthenticated RCE, while no patches are currently available.

    02040315
    1.5K followersView on X
  • xit! 🇮🇳@xitsec
    Patch

    https://ethicalnews.in/august-2026-patch-tuesday-what-to-patch-first-afd-sys-zero-day-and-a-wormable-dns-rce/ CVE-2026-62878 : If you run Windows DNS anywhere that can receive queries from untrusted networks, this is your number-one action item this month — ahead of the zero-day. Patch it

    Post summary

    The text is a simple patch advisory for CVE-2026-62878, urging administrators to update Windows DNS before the zero-day is addressed.

    00031613
    3.7K followersView on X
  • kawn@kawn2020
    Disclosure

    #windowsupdate #microsoft つづき ・CVE-2026-62878 Windows DNS サーバーのリモートでコードが実行される脆弱性 ・CVE-2026-62893 Windows 展開サービス TFTP Server のリモートでコードが実行される脆弱性 ・CVE-2026-65789 Windows DNS サーバーのリモートでコードが実行される脆弱性

    Post summary

    The tweet announces three newly disclosed Windows DNS/TFTP Server remote code execution vulnerabilities (CVE-2026-62878, 62893, 65789) without providing PoC, exploit, or patch details.

    1001099
    87 followersView on X
  • lee1981@lee1981b
    Patch

    🔥 CyberForge CVE of the Day #028 🚨 CVE-2026-62878 — Microsoft has patched a Critical unauthenticated RCE in Windows DNS Server. A remote attacker could exploit a stack-based buffer overflow over the network—no credentials or user interaction required. Microsoft describes the root cause as a stack-based buffer overflow: an unauthorised attacker can send network input to a vulnerable DNS service and, if exploitation succeeds, execute attacker-controlled code. No account, prior foothold, or victim interaction is required. Its 9.8 CVSS score is driven by the worst possible combination for a server-side flaw: network reachability, low attack complexity, no required privileges, no user interaction, and high confidentiality, integrity, and availability impact. Microsoft published fixes in the August 2026 security updates. 🔑 Key details: ⭐ Severity: Critical — CVSS 9.8 🧠 Weakness: CWE-121 🎯 Target: Windows DNS Server 🔓 Authentication: None 👆 User interaction: None ⚔️ Impact: Remote code execution 🛡️ Fix: August 2026 Windows security updates 🦠 ZDI assessment: Wormable potential 📊 Microsoft assessment: Exploitation Less Likely 🚫 No confirmed active exploitation or credible public PoC found 📋 CISA KEV: Not listed as of 19 August 2026 ⚠️ Why it matters: Windows DNS frequently sits at the heart of Active Directory and may run directly on domain controllers. Successful exploitation could place an attacker on Tier-0 infrastructure, while failed exploitation may still crash DNS and disrupt authentication, name resolution, and critical services. 🛡️Affected Software, Microsoft's CNA data lists the following product families: - Windows Server 2012 and Server Core installation - Windows Server 2012 R2 and Server Core installation - Windows Server 2016 and Server Core installation - Windows Server 2019 and Server Core installation - Windows Server 2022 - Windows Server 2025 and Server Core installation - Windows 10 Version 1607, 32-bit and x64 editions - Windows 10 Version 1809, 32-bit and x64 editions 🧠 The practical attack surface is the Windows DNS Server component when it is installed, running, and reachable. Microsoft includes Windows 10 SKUs because affected Windows component code and servicing metadata can span multiple products; a Windows endpoint that is not providing the DNS Server service is not equivalent to an exposed DNS server. Validate the actual role/component and service state rather than treating every listed Windows device identically. 🔥 CyberForge verdict: Patch immediately. Prioritise internet-facing DNS, DNS-hosting domain controllers, and critical internal resolvers. “Wormable” is presently a ZDI assessment—not evidence of an active worm. 🔗 Full visual advisory: https://github.com/advisories/GHSA-6f49-r342-pg5p 🔗 Full vulnerability details: https://nvd.nist.gov/vuln/detail/CVE-2026-62878 #CyberSecurity #CVE #Microsoft #WindowsServer #DNS #RCE #PatchTuesday #CyberForge

    Post summary

    Microsoft released a patch for a critical unauthenticated RCE in Windows DNS Server (CVE‑2026‑62878), with no active exploitation reported or public PoC available.

    00020229
    624 followersView on X
  • ExploitGrid@exploitgrid

    💀 CRITICAL Exploits Trending ├ CVE-2026-27626 · CVE-2026-86218 · PoC live ├ CVE-2020-14645 — WebLogic · PoC live (still getting hit 6 yrs later) └ CVE-2026-5118 · CVE-2026-62878 · PoC live

    1000045
    47 followersView on X
  • ExploitGrid@exploitgrid

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: CVE-2026-27626 CVE-2026-86218 CVE-2020-14645 CVE-2026-5118 CVE-2026-62878 ..🧵👇

    1000045
    47 followersView on X
  • ExploitGrid@exploitgrid

    [EXPLOIT] CVE-2026-62878 [CRITICAL/PoC] CVE-2026-62878 🔗 https://exploitgrid.net/exploits/d187e212-ed77-4639-98b5-998772add9df

    1000033
    47 followersView on X
  • Tochukwu Okonkwor@tokonkwor
    Patch

    ZDI's Dustin Childs on August's DNS flaw: wormable, and he would not trust Microsoft's "less likely" rating. Patch internet-facing DNS first. One correction: the wormable one is CVE-2026-62878. The 62817 going around is a different DNS RCE in the same batch.

    Post summary

    The message urges patching of internet‑facing DNS for CVE‑2026‑62878, noting its wormable nature and distinguishing it from a different DNS RCE CVE‑2026‑62817.

    1000045
    24 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    Windows DNS ServerにCVSS 9.8の認証不要RCE、8月更新を適用 #it #Cybersecurity https://www.cybernote.click/2026/08/14/windows-dns-server-cve-2026-62878-rce/

    Post summary

    The post highlights a high‑severity, unauthenticated RCE in Windows DNS Server and notes that an August patch update has been applied.

    0001078
    213 followersView on X
  • Human Firewall@HumanFirewallHQ
    Patch

    The 9.8s: CVE-2026-62878 — Windows DNS Server, stack-based buffer overflow, no interaction, WORMABLE. ZDI's advice: test fast, patch internet-facing DNS first. CVE-2026-62815 — Microsoft QUIC, RCE, no auth, no user interaction. Internet-facing = tonight's work.

    Post summary

    The post reports two critical CVEs—Windows DNS Server with a stack buffer overflow and Microsoft QUIC RCE—and urges rapid testing and patching of internet-facing DNS services.

    1000060
    2 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Attention, elevated activities detected targeting Microsoft Windows (CVE-2026-62878) https://vuldb.com/vuln/388578/cti

    Post summary

    The post alerts that elevated, presumably malicious activity has been detected against Microsoft Windows related to CVE-2026-62878, implying potential real‑world exploitation, but provides no PoC, exploit code, patch, or detailed technical information.

    01000153
    2.3K followersView on X
  • VulniPulse@vulnipulse
    Patch

    🚨 CRITICAL CVE ALERT CVE-2026-62878 · Microsoft Windows Server 2019 · CVSS 9.8 Attackers could execute arbitrary code. Upgrade to a vendor-listed fixed release. 🔎 Full advisory: https://vulnipulse.com/advisories/microsoft-cve-2026-62878 #CyberSecurity #CVE #Microsoft #WindowsServer

    Post summary

    CVE-2026-62878 is a critical vulnerability in Windows Server 2019 (CVSS 9.8) that allows arbitrary code execution. Users should upgrade to the vendor‑listed fixed release.

    1000062
    7 followersView on X
  • dbugs@ptdbugs

    A PoC/exploit has been discovered for vulnerability CVE-2026-62878 PT ID: PT-2026-70575 Vendor: Microsoft Product: Windows DNS Server Description: A stack-based buffer overflow vulnerability in Windows DNS Server allows an unauthenticated remote attacker to corrupt memory by sending specially crafted DNS queries. Successful exploitation can lead to denial of service and may allow arbitrary code execution in the context of the DNS Server process. Microsoft classifies the vulnerability as a remote code execution vulnerability. References: • https://dbu.gs/vulnerability/PT-2026-70575 • https://github.com/nomi-sec/PoC-in-GitHub

    00000344
    3.6K followersView on X
  • Tochukwu Okonkwor@tokonkwor
    Disclosure

    The wormable Windows DNS Server flaw from Tuesday is CVE-2026-62878, CVSS 9.8. Unauthenticated, remote, no user interaction. CVE-2026-62817 is a different DNS RCE in the same batch. Both worth patching. Only one is wormable. Internet-facing DNS first.

    Post summary

    The post announces two Windows DNS Server vulnerabilities, one wormable, notes high severity, and recommends patching though no PoC or active exploitation is referenced.

    0000030
    24 followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Patch

    Critical CVEs (Aug 24): Windows DNS Server RCE (CVE-2026-62878) & GitLab code injection (CVE-2026-19478) threaten data privacy/integrity in transit. Patch urgently! #Cybersecurity #ZeroDay #NetworkSecurity

    Post summary

    The post cites two critical CVEs, notes their impact on data privacy, and urges users to apply patches immediately.

    0000080
    17 followersView on X
  • Internet Secure Services株式会社@iss_kk_official
    Patch

    【技術解説】Windows DNS Serverのワーム化するRCE、CVE-2026-62878(CVSS 9.8)が今月の最重要パッチ。 8月Patch Tuesdayの本命はWindows DNSのCVE-2026-62878。ユーザー操作不要のスタックオーバーフローでRCE、しかもワーム化しうる。DNSは境界の内側で信頼されがち。外部解決を担うサーバは即パッチ+egress制御を。放置は横展開の踏み台になる。 #CVE #パッチ管理 #Windows

    Post summary

    The post highlights a critical RCE vulnerability in Windows DNS Server and stresses the need for immediate patching and egress controls to prevent potential worm-like propagation.

    0000068
    8 followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Patch

    New critical RCEs in MS QUIC (CVE-2026-62815) & Windows DNS (CVE-2026-62878) demand urgent patching to protect data. Also, MLflow SSRF (CVE-2026-64849) exposes internal services. Act now! #Cybersecurity #Vulnerabilities #NetSec

    Post summary

    The post warns of critical RCE and SSRF vulnerabilities and urges immediate patching to protect data.

    0000078
    17 followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Disclosure

    New critical RCEs: MS QUIC (CVE-2026-62815), Kemp LoadMaster (CVE-2026-8037), S2OPC (Aug 18), & Win DNS (CVE-2026-62878) threaten data privacy/integrity in transit. Patch NOW! #Cybersecurity #Vulnerabilities #InfoSec

    Post summary

    The post announces new critical remote code execution CVEs affecting MS QUIC, Kemp LoadMaster, S2OPC, and Win DNS, and urges immediate patching.

    0000060
    17 followersView on X
  • National CERT/CC@CERT_UG
    Patch

    🚨 August 19, 2026 Patch Advisories Today's advisories target these CVEs; - Microsoft Defender ShieldBreak (CVE-2026-69414) - SharePoint full RCE chain (CVE-2026-55040 and CVE-2026-63520 - Windows DNS Server (CVE-2026-62878, CVSS 9.8) https://cert.ug | #CyberSafeUG https://t.co/wPfwnCGltI

    Post summary

    The tweet announces patch advisories for several CVEs, including a high‑scoring DNS server flaw (CVSS 9.8) and a SharePoint RCE chain, urging users to apply vendor patches.

    00000182
    1.4K followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2025---

Explore more