Windows DHCP Server Denial of Service Vulnerability
MonitorCVSS 5.7CVE-2026-69416Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A buffer over-read vulnerability in Windows DHCP Server (CVE-2026-69416) allows an authorized attacker on the local or adjacent network to deny service by sending a malformed DHCP request, causing the DHCP service to crash and preventing IP address assignment to network clients. Affected versions include Windows 10 (versions 1607 and 1809), Windows Server 2016, 2019, 2022, and 2025. Microsoft has released security patches for all affected versions.
What this means
What could happen
An attacker with network access to your DHCP server could send a malformed DHCP request to cause the service to crash, disrupting IP address assignment for all connected devices and potentially halting network operations across your facility.
Who's at risk
Water authorities and municipal utilities using Windows Server for DHCP services, particularly those running Windows Server 2016, 2019, 2022, or 2025. Any organization relying on a Windows DHCP server for IP address assignment to control systems, workstations, or network devices is affected.
How it could be exploited
An attacker positioned on the local network (same subnet or adjacent network segment) crafts a specially malformed DHCP packet and sends it to your Windows DHCP server. The buffer over-read flaw in the DHCP service causes it to crash, denying service to all devices attempting to lease or renew IP addresses.
Prerequisites
- Network access to DHCP server port 67 (UDP) from adjacent network segment
- Valid DHCP client credentials or ability to send DHCP requests (generally low barrier on open networks)
- DHCP server service running on Windows 10, Windows Server 2016, 2019, 2022, or 2025
low complexity attackrequires local network proximitymedium CVSS scoredenial of service impactauthentication required (DHCP protocol level)
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict network access to DHCP ports (UDP 67/68) to only authorized DHCP clients and relay agents using your network firewall or access control lists
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the September 2026 Microsoft security update to your Windows DHCP servers
Long-term hardening
0/1HARDENINGImplement network segmentation to limit which devices can reach your DHCP server
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/f11a79cb-a520-40a9-9ce0-4eeecaabf8a5Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.