everyone rushed to patch the SharePoint zero-day. the 9.8 sitting on your DHCP server is the one that scares me

CVE-2026-50518 is an unauthenticated remote code execution flaw in Windows DHCP Server — no login, no clicks, network access is the only…

Aliteq
Priya Nair · Software & Systems Editor

What you need to know

The flaw: a heap-based buffer overflow in Windows DHCP Server that allows unauthenticated remote code execution (CWE — memory corruption). Vector: AV:N/AC:L/PR:N/UI:N.

What you need to know

Affected: Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025 — any server running the DHCP Server role.

What you need to know

No exploitation confirmed yet, but Microsoft labels it 'Exploitation More Likely,' and unauthenticated 9.8s attract exploit development fast.

What you need to know

Not the same as the SharePoint/AD FS zero-days everyone patched first — this is a separate critical that's easy to overlook.

What you need to know

Fix: the July 2026 security update. If you can't patch a DHCP server immediately, restrict who can reach it at the network layer.

Don't triage on 'no known exploitation'

It's tempting to deprioritise a bug that isn't yet exploited in favour of the two that are. That's backwards for an unauthenticated 9.8 on core infrastructure — 'not yet' is a window, not a…

Aliteq

Read the full story

everyone rushed to patch the SharePoint zero-day. the 9.8 sitting on your DHCP server is the one that scares me

Read the full story on Aliteq