Abstract illustration of connected devices separated by a protected security boundary.
Microsoft’s September 22, 2026 security release fixes CVE-2026-77886, an Important Windows DHCP Server denial-of-service vulnerability affecting listed Windows 10 and Windows Server installations; administrators must deploy the matching KB and verify the prescribed fixed build, because Microsoft says customer action is required.

Microsoft Security Response Center classifies the flaw as an out-of-bounds read and assigns a 7.5 CVSS base score. The immediate operational concern is service availability: an unauthorized attacker can deny service over a network, making patch deployment a DHCP infrastructure maintenance priority rather than a desktop-only update exercise.

CVE-2026-77886 is a Windows DHCP Server denial-of-service flaw​

Microsoft’s official title for CVE-2026-77886 is Windows DHCP Server Denial of Service Vulnerability. The advisory’s stated finding is: “Windows DHCP Server Denial of Service Vulnerability: Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.”

The weakness is CWE-125, Out-of-bounds Read. Microsoft describes the condition as an out-of-bounds read in Windows DHCP Server that permits an unauthorized attacker to deny service over a network.

Microsoft rates CVE-2026-77886 as Important, with a CVSS base score of 7.5 and a temporal score of 6.5. Its full CVSS vector is:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C

The vector identifies a network attack path with low attack complexity, no privileges required, and no user interaction required. Its impact component is confined to availability, with high availability impact and no confidentiality or integrity impact.

Microsoft’s current advisory status is:

  • Publicly disclosed: No
  • Exploited: No
  • Customer action required: Yes

Microsoft’s exploitation assessment is Exploitation Less Likely. That assessment should guide prioritization, but it does not change the remediation requirement for organizations running an affected DHCP Server installation.

The CVE-2026-77886 fix spans legacy Windows and Windows Server releases​

CVE-2026-77886 has a broad supported-product list, covering Windows 10 Version 1607 and Version 1809 as well as Windows Server 2012 through Windows Server 2025. The update is supplied through five KB packages, each tied to a specific fixed build.

The practical point for patch management is that there is no single KB number for every affected machine. Windows Server 2012 and Windows Server 2012 R2 have separate packages; Windows Server 2016 shares its package with Windows 10 Version 1607; and Windows Server 2019 shares its package with Windows 10 Version 1809.

Microsoft’s remediation mapping is as follows:

Affected productMicrosoft remediation
Windows 10 Version 1607 for 32-bit Systems (x86)For Windows 10 Version 1607 for 32-bit Systems (x86), install KB5123099 to reach fixed build 10.0.14393.9512.
Windows 10 Version 1607 for x64-based SystemsFor Windows 10 Version 1607 for x64-based Systems, install KB5123099 to reach fixed build 10.0.14393.9512.
Windows 10 Version 1809 for 32-bit Systems (x86)For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5122876 to reach fixed build 10.0.17763.9245.
Windows 10 Version 1809 for x64-based SystemsFor Windows 10 Version 1809 for x64-based Systems, install KB5122876 to reach fixed build 10.0.17763.9245.
Windows Server 2012 (Server Core installation) (x64)For Windows Server 2012 (Server Core installation) (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
Windows Server 2012 (x64)For Windows Server 2012 (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
Windows Server 2012 R2 (Server Core installation) (x64)For Windows Server 2012 R2 (Server Core installation) (x64), install KB5123066 to reach fixed build 6.3.9600.23397.
Windows Server 2012 R2 (x64)For Windows Server 2012 R2 (x64), install KB5123066 to reach fixed build 6.3.9600.23397.
Windows Server 2016 (Server Core installation) (x64)For Windows Server 2016 (Server Core installation) (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
Windows Server 2016 (x64)For Windows Server 2016 (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
Windows Server 2019 (Server Core installation) (x64)For Windows Server 2019 (Server Core installation) (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
Windows Server 2019 (x64)For Windows Server 2019 (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
Windows Server 2022 (Server Core installation) (x64)For Windows Server 2022 (Server Core installation) (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
Windows Server 2022 (x64)For Windows Server 2022 (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
Windows Server 2025 (Server Core installation) (x64)For Windows Server 2025 (Server Core installation) (x64), install KB5122871 to reach fixed build 10.0.26100.33438.
Windows Server 2025 (x64)For Windows Server 2025 (x64), install KB5122871 to reach fixed build 10.0.26100.33438.

Fixed build verification is the useful completion test for CVE-2026-77886​

Installing a KB is the remediation action Microsoft specifies, but the authoritative verification target is the resulting operating-system build. That matters in managed environments where update approval, deployment, and installation reporting may occur at different times.

For Windows Server 2025, the target is build 10.0.26100.33438 after KB5122871. Windows Server 2022 requires KB5122882 and build 10.0.20348.5622. Windows Server 2019 requires KB5122876 and build 10.0.17763.9245, while Windows Server 2016 requires KB5123099 and build 10.0.14393.9512.

The older server branches need their own checks. Windows Server 2012 must reach 6.2.9200.26349 through KB5123065, and Windows Server 2012 R2 must reach 6.3.9600.23397 through KB5123066. The same builds and KB mappings apply to the listed Server Core installations, so Core systems should remain in the same deployment and verification scope as their full-server counterparts.

What this means for you​

Administrators with DHCP Server workloads on the affected Windows releases should schedule the corresponding Microsoft update, then confirm that each server reaches its designated fixed build before treating CVE-2026-77886 as remediated.

  • Deploy KB5122871 to affected Windows Server 2025 installations and confirm fixed build 10.0.26100.33438.
  • Deploy KB5122882 to affected Windows Server 2022 installations and confirm fixed build 10.0.20348.5622.
  • Deploy KB5122876 to affected Windows Server 2019 installations and listed Windows 10 Version 1809 systems, then confirm fixed build 10.0.17763.9245.
  • Deploy KB5123099 to affected Windows Server 2016 installations and listed Windows 10 Version 1607 systems, then confirm fixed build 10.0.14393.9512.
  • Deploy KB5123065 for Windows Server 2012 or KB5123066 for Windows Server 2012 R2, using the corresponding fixed-build target for each release.
  • Treat Server Core as a separately inventoried installation type, while applying the same KB and build target Microsoft specifies for that Windows Server version.

CVE-2026-77886 is an availability-focused Windows DHCP Server vulnerability with a direct, version-specific update path. Microsoft’s assessment that exploitation is less likely informs urgency planning, but its customer-action requirement makes the decision straightforward: identify affected DHCP Server installations, apply the matching KB, and verify the fixed build recorded for that product.