Windows DNS Server Unauthenticated Remote Code Execution Patched in August Patch Tuesday (CVE-2026-62878)
Scope: Windows Server 2019, 2022, and 2025 with DNS Server Role Installed
Severity: Red
CVE-2026-62878 (CVSS 9.8) is one of four unauthenticated network-reachable remote code execution flaws addressed in Microsoft's August 2026 Patch Tuesday, allowing a remote unauthenticated attacker to execute arbitrary code with elevated privileges on Windows DNS Servers with no user interaction, credentials, or special conditions required. Zero Day Initiative specifically highlighted this flaw as the standout of the four unauthenticated 9.8 flaws given that DNS is a fundamental service on every Windows Server domain environment, meaning exploitation would be reachable on virtually every enterprise and government Windows network from any external or internal position. Although not confirmed exploited in the wild at time of patching, the attack surface and ease of exploitation place this among the highest-priority patches in today's release. Organizations must apply the August 2026 cumulative update to all Windows Server DNS role instances immediately, prioritizing internet-facing and domain controller-adjacent servers first.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.