Microsoft’s advisory names the issue Windows DHCP Server Denial of Service Vulnerability. It is tracked as CVE-2026-69637 and is rated Important, with a CVSS base score of 5.7 and a temporal score of 5.0.
CVE-2026-69637 targets Windows DHCP Server availability
Microsoft describes CVE-2026-69637 as an out-of-bounds read in Windows DHCP Server that allows an authorized attacker to deny service over an adjacent network. In operational terms, the consequence identified by the advisory is loss of DHCP service availability, which can prevent clients from receiving or renewing network configuration supplied by the server.
The CVSS v3.1 vector is CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C. The adjacent-network attack vector means the advisory’s attack path is scoped to a network position next to the target, while the low attack complexity and absence of required user interaction place the remediation burden on server administrators rather than on end users.
The score’s impact fields identify availability as the affected security property: confidentiality and integrity are both recorded as having no impact, while availability is rated High. The vulnerability is associated with CWE-125 and CWE-843.
Microsoft’s published advisory fact is explicit: “Windows DHCP Server Denial of Service Vulnerability: Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.”
The advisory status fields are:
- Publicly disclosed: No
- Exploited: No
- Customer action required: Yes
Microsoft’s exploitation assessment is Exploitation Less Likely. That assessment is useful for prioritization, but it does not remove the practical need to patch DHCP servers: the vulnerable service is responsible for a foundational network function, and Microsoft has explicitly marked customer action as required.
Microsoft maps CVE-2026-69637 to six KB packages
The affected-product list covers older Windows Server generations, their Server Core installation variants, and selected Windows 10 releases. The key administrative detail is that the same KB can cover more than one product family, but the expected fixed build is tied to the specific servicing branch.
For Windows 10 Version 1607 and Windows Server 2016, Microsoft maps CVE-2026-69637 to KB5123099 and fixed build 10.0.14393.9512. Windows 10 Version 1809 and Windows Server 2019 use KB5122876 and fixed build 10.0.17763.9245.
Windows Server 2012 and Windows Server 2012 R2 receive separate packages, KB5123065 and KB5123066 respectively. The newer server releases use KB5122882 for Windows Server 2022 and KB5122871 for Windows Server 2025.
| Affected product | Required update | Vendor fixed version |
|---|---|---|
| Windows 10 Version 1607 for 32-bit Systems (x86) | KB5123099 | 10.0.14393.9512 |
| Windows 10 Version 1607 for x64-based Systems | KB5123099 | 10.0.14393.9512 |
| Windows 10 Version 1809 for 32-bit Systems (x86) | KB5122876 | 10.0.17763.9245 |
| Windows 10 Version 1809 for x64-based Systems | KB5122876 | 10.0.17763.9245 |
| Windows Server 2012 (Server Core installation) (x64) | KB5123065 | 6.2.9200.26349 |
| Windows Server 2012 (x64) | KB5123065 | 6.2.9200.26349 |
| Windows Server 2012 R2 (Server Core installation) (x64) | KB5123066 | 6.3.9600.23397 |
| Windows Server 2012 R2 (x64) | KB5123066 | 6.3.9600.23397 |
| Windows Server 2016 (Server Core installation) (x64) | KB5123099 | 10.0.14393.9512 |
| Windows Server 2016 (x64) | KB5123099 | 10.0.14393.9512 |
| Windows Server 2019 (Server Core installation) (x64) | KB5122876 | 10.0.17763.9245 |
| Windows Server 2019 (x64) | KB5122876 | 10.0.17763.9245 |
| Windows Server 2022 (Server Core installation) (x64) | KB5122882 | 10.0.20348.5622 |
| Windows Server 2022 (x64) | KB5122882 | 10.0.20348.5622 |
| Windows Server 2025 (Server Core installation) (x64) | KB5122871 | 10.0.26100.33438 |
| Windows Server 2025 (x64) | KB5122871 | 10.0.26100.33438 |
A server’s installation style does not change the prescribed update within a given Windows Server release. For example, both the Server Core installation and full Windows Server 2022 installation require KB5122882 and the same 10.0.20348.5622 fixed build.
CVE-2026-69637 remediation is defined by the installed servicing branch
Microsoft’s remediation values should be applied exactly to the operating-system release and architecture in use:
- For Windows 10 Version 1607 for 32-bit Systems (x86), install KB5123099 to reach fixed build 10.0.14393.9512.
- For Windows 10 Version 1607 for x64-based Systems, install KB5123099 to reach fixed build 10.0.14393.9512.
- For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5122876 to reach fixed build 10.0.17763.9245.
- For Windows 10 Version 1809 for x64-based Systems, install KB5122876 to reach fixed build 10.0.17763.9245.
- For Windows Server 2012 (Server Core installation) (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
- For Windows Server 2012 (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
- For Windows Server 2012 R2 (Server Core installation) (x64), install KB5123066 to reach fixed build 6.3.9600.23397.
- For Windows Server 2012 R2 (x64), install KB5123066 to reach fixed build 6.3.9600.23397.
- For Windows Server 2016 (Server Core installation) (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
- For Windows Server 2016 (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
- For Windows Server 2019 (Server Core installation) (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
- For Windows Server 2019 (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
- For Windows Server 2022 (Server Core installation) (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
- For Windows Server 2022 (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
- For Windows Server 2025 (Server Core installation) (x64), install KB5122871 to reach fixed build 10.0.26100.33438.
- For Windows Server 2025 (x64), install KB5122871 to reach fixed build 10.0.26100.33438.
The presence of Windows 10 entries should be interpreted narrowly. CVE-2026-69637 concerns Windows DHCP Server, and the relevant question for a Windows 10 estate is whether an affected device actually provides that role or is otherwise within the product scope Microsoft identifies. The update mapping itself remains release- and architecture-specific.
What this means for you
Patch and verify systems that provide Windows DHCP Server, beginning with the versions identified by Microsoft and using the KB assigned to each operating-system branch. The available evidence supports prioritizing service continuity: CVE-2026-69637 is a denial-of-service flaw with High availability impact, and the advisory requires customer action.
- Administrators of Windows Server 2025 should deploy KB5122871 and verify fixed build 10.0.26100.33438 on both Windows Server 2025 (x64) and Windows Server 2025 (Server Core installation) (x64).
- Administrators of Windows Server 2022 should deploy KB5122882 and verify fixed build 10.0.20348.5622 on both listed installation types.
- Windows Server 2019 and Windows 10 Version 1809 deployments in scope require KB5122876 and fixed build 10.0.17763.9245.
- Windows Server 2016 and Windows 10 Version 1607 deployments in scope require KB5123099 and fixed build 10.0.14393.9512.
- Windows Server 2012 requires KB5123065 and fixed build 6.2.9200.26349, while Windows Server 2012 R2 requires KB5123066 and fixed build 6.3.9600.23397.
- Asset and patch-management records should distinguish Server Core installations from full installations even where Microsoft assigns them the same KB, so that every DHCP Server role holder is accounted for during rollout.
CVE-2026-69637 is a contained but operationally meaningful Windows DHCP Server issue: Microsoft rates it Important, assesses exploitation as less likely, and supplies a clear KB-and-build destination for every affected branch. The immediate administrative task is therefore straightforward—identify DHCP Server hosts in the listed Windows releases, deploy the corresponding update, and confirm they have reached Microsoft’s fixed build.