Abstract illustration of connected devices separated by a protected security boundary.
Microsoft has issued fixes for CVE-2026-69405, Windows DHCP Server Denial of Service Vulnerability, an Important Windows DHCP Server flaw that can allow an authorized attacker on an adjacent network to deny service. The practical priority is clear for administrators running DHCP on the affected Windows Server releases: deploy the matching cumulative update and verify that the server has reached Microsoft’s specified fixed build.

Microsoft’s Security Response Center published the advisory on September 11, 2026. Its record assigns a CVSS base score of 5.7 and a temporal score of 5.0, with the vector CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C. Microsoft rates the issue Important, identifies CWE-401, and says Customer action required: Yes.

Microsoft’s advisory uses two closely related descriptions. It describes “Windows DHCP Server Denial of Service Vulnerability: Uncontrolled resource consumption in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.” It also specifies: “Windows DHCP Server Denial of Service Vulnerability: Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.”

The impact is availability rather than confidentiality or integrity. The supplied CVSS vector records no confidentiality or integrity impact and a high availability impact; in operational terms, the concern is a DHCP service disruption, which can prevent clients from obtaining or renewing network configuration when the service is affected.

Microsoft’s status fields are explicit: Publicly disclosed: No. Exploited: No. Microsoft’s exploitation assessment is Exploitation Unlikely.

A DHCP Server update requires build-level verification​

CVE-2026-69405 is an adjacent-network issue, and Microsoft’s description requires an authorized attacker. That narrows the stated attack conditions, but it does not turn the update into optional maintenance for a server that provides address leases or network settings to production clients. DHCP availability is a shared dependency: a service outage can affect more systems than the server itself, particularly as existing leases approach renewal.

The affected-product record covers both full and Server Core installations across Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025. It also lists Windows 10 Version 1607 and Windows 10 Version 1809 in 32-bit and x64 forms.

This is an important distinction for patch management. The applicable update is determined by the operating-system servicing branch, rather than by whether the machine uses a graphical installation or Server Core: Server Core and full-server variants within each listed branch use the same KB and target build. Administrators should therefore validate the installed cumulative update and resulting OS build on systems that actually host the Windows DHCP Server role.


Microsoft’s KB5123065 and KB5123066 fixes for Windows Server 2012​

For Windows Server 2012 (Server Core installation) (x64), install KB5123065 to reach fixed build 6.2.9200.26349.

For Windows Server 2012 (x64), install KB5123065 to reach fixed build 6.2.9200.26349.

For Windows Server 2012 R2 (Server Core installation) (x64), install KB5123066 to reach fixed build 6.3.9600.23397.

For Windows Server 2012 R2 (x64), install KB5123066 to reach fixed build 6.3.9600.23397.

The separate KBs and build targets matter when update compliance data is consolidated across older server fleets. Windows Server 2012 and Windows Server 2012 R2 are different servicing baselines, so an inventory report that merely says “patched” is less useful than one showing KB5123065 with build 6.2.9200.26349 for Windows Server 2012, or KB5123066 with build 6.3.9600.23397 for Windows Server 2012 R2.

KB5123099 covers the 14393 branch​

For Windows 10 Version 1607 for 32-bit Systems (x86), install KB5123099 to reach fixed build 10.0.14393.9512.

For Windows 10 Version 1607 for x64-based Systems, install KB5123099 to reach fixed build 10.0.14393.9512.

For Windows Server 2016 (Server Core installation) (x64), install KB5123099 to reach fixed build 10.0.14393.9512.

For Windows Server 2016 (x64), install KB5123099 to reach fixed build 10.0.14393.9512.

The shared target build is the useful deployment check for the Windows 10 Version 1607 and Windows Server 2016 branch. On a DHCP host, reaching 10.0.14393.9512 is the documented remediation point for CVE-2026-69405; it is more concrete than treating the vulnerability record as proof that every system on the branch has received the fix.

KB5122876 applies to the 17763 branch​

For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5122876 to reach fixed build 10.0.17763.9245.

For Windows 10 Version 1809 for x64-based Systems, install KB5122876 to reach fixed build 10.0.17763.9245.

For Windows Server 2019 (Server Core installation) (x64), install KB5122876 to reach fixed build 10.0.17763.9245.

For Windows Server 2019 (x64), install KB5122876 to reach fixed build 10.0.17763.9245.

Windows Server 2019 DHCP systems should therefore be checked against build 10.0.17763.9245 after KB5122876 deployment. The same KB and build appear for Windows 10 Version 1809, but the immediate administrative focus should be systems on which Windows DHCP Server is installed and active.

Windows Server 2022 and Windows Server 2025 targets​

For Windows Server 2022 (Server Core installation) (x64), install KB5122882 to reach fixed build 10.0.20348.5622.

For Windows Server 2022 (x64), install KB5122882 to reach fixed build 10.0.20348.5622.

For Windows Server 2025 (Server Core installation) (x64), install KB5122871 to reach fixed build 10.0.26100.33438.

For Windows Server 2025 (x64), install KB5122871 to reach fixed build 10.0.26100.33438.

Microsoft’s advisory gives administrators an unusually usable closure condition: each affected servicing branch has a named KB and a fixed build. For CVE-2026-69405, the deployment record should show KB5123065 and 6.2.9200.26349, KB5123066 and 6.3.9600.23397, KB5123099 and 10.0.14393.9512, KB5122876 and 10.0.17763.9245, KB5122882 and 10.0.20348.5622, or KB5122871 and 10.0.26100.33438, as applicable to the Windows DHCP Server host.