Windows DHCP Server Denial of Service Vulnerability

MonitorCVSS 5.7CVE-2026-69416Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A buffer over-read vulnerability in Windows DHCP Server (CVE-2026-69416) allows an authorized attacker on the local or adjacent network to deny service by sending a malformed DHCP request, causing the DHCP service to crash and preventing IP address assignment to network clients. Affected versions include Windows 10 (versions 1607 and 1809), Windows Server 2016, 2019, 2022, and 2025. Microsoft has released security patches for all affected versions.

What this means
What could happen
An attacker with network access to your DHCP server could send a malformed DHCP request to cause the service to crash, disrupting IP address assignment for all connected devices and potentially halting network operations across your facility.
Who's at risk
Water authorities and municipal utilities using Windows Server for DHCP services, particularly those running Windows Server 2016, 2019, 2022, or 2025. Any organization relying on a Windows DHCP server for IP address assignment to control systems, workstations, or network devices is affected.
How it could be exploited
An attacker positioned on the local network (same subnet or adjacent network segment) crafts a specially malformed DHCP packet and sends it to your Windows DHCP server. The buffer over-read flaw in the DHCP service causes it to crash, denying service to all devices attempting to lease or renew IP addresses.
Prerequisites
  • Network access to DHCP server port 67 (UDP) from adjacent network segment
  • Valid DHCP client credentials or ability to send DHCP requests (generally low barrier on open networks)
  • DHCP server service running on Windows 10, Windows Server 2016, 2019, 2022, or 2025
low complexity attackrequires local network proximitymedium CVSS scoredenial of service impactauthentication required (DHCP protocol level)
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict network access to DHCP ports (UDP 67/68) to only authorized DHCP clients and relay agents using your network firewall or access control lists
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the September 2026 Microsoft security update to your Windows DHCP servers
Long-term hardening
0/1
HARDENINGImplement network segmentation to limit which devices can reach your DHCP server
API: /api/v1/advisories/f11a79cb-a520-40a9-9ce0-4eeecaabf8a5

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.