microsoft just patched a Windows bug that could worm through every DNS server on earth

CVE-2026-62878 is a 9.8-severity, zero-click hole in Windows DNS Server. Microsoft rates it 'exploitation less likely.' The researchers who track…

Aliteq
Priya Nair · Software & Systems Editor

The short version

CVE-2026-62878: critical (CVSS 9.8) stack-based buffer overflow in Windows DNS Server, unauthenticated and remote, patched August 11, 2026.

The short version

It targets any server running the Windows DNS Server role — including Active Directory domain controllers, where DNS is commonly installed by default.

The short version

Microsoft calls exploitation 'less likely'; Trend Micro's Zero Day Initiative calls the bug wormable and disagrees with that rating.

The short version

No confirmed in-the-wild exploitation yet — this is a patch-before-it-happens bug, not a patch-because-it-happened one.

The short version

The same Patch Tuesday also fixed CVE-2026-62893 (Windows Deployment Services, also CVSS 9.8) and CVE-2026-68820, the one bug actually being exploited right now.

My honest take

I'd patch this one before the confirmed-exploited zero-day, not after. CVE-2026-68820 needs an attacker already running code on your machine; CVE-2026-62878 needs nothing but a network path to a DNS…

Aliteq

Read the full story

microsoft just patched a Windows bug that could worm through every DNS server on earth

Read the full story on Aliteq