type: cve ยท created: 2026-08-12 ยท updated: 2026-08-12 ยท tags: [cve, rce, microsoft, dns-server, wormable, stack-overflow, unauthenticated, patch-tuesday] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government, finance, healthcare, energy, defence] ยท au_impact: true
CVE-2026-62878 โ Windows DNS Server Stack Buffer Overflow RCE
CVE-2026-62878 is an unauthenticated remote code execution (RCE) vulnerability in Microsoft Windows DNS Server โ a stack buffer overflow that ZDI describes as wormable โ rated CVSS 9.8 and shipped in the August 2026 Patch Tuesday release (2026-08-11).
Vulnerability Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-62878 |
| Type | Unauthenticated remote code execution (RCE); stack buffer overflow |
| Product | Microsoft Windows DNS Server |
| Access | Unauthenticated |
| CVSS | 9.8 |
| Wormable | Per ZDI |
| Exploitation status | Not flagged as actively exploited in the wild in the August 2026 release |
Context
Patched in Microsoft's August 2026 Patch Tuesday (398 CVEs, 62 Critical per ZDI). The flaw is one of four unauthenticated RCEs at CVSS 9.8 in the release. Windows DNS Server is exposed in almost every corporate network and NZISM-covered Windows estate, making this a priority patch; the digest flags DNS Server and QUIC as platforms NZISM-covered systems run.
Related Pages
- Microsoft Patches 398 Flaws Including A Windows Driver Zero Day Under Active Att โ the August 2026 Patch Tuesday release
Sources: raw/digests/Cyber-Digest-2026-08-12