About this tag
The dhcp security tag covers Microsoft Windows DHCP Server vulnerabilities addressed in the July 14, 2026 security updates. Tagged discussions examine CVE-2026-50685, CVE-2026-50518, CVE-2026-50370, and CVE-2026-48564, including remote code execution risks involving double-free memory errors, heap-based buffer overflows, and improper input validation. The posts compare Microsoft severity ratings and CVSS scores from 7.5 to 9.8, along with whether attacks require authentication, user interaction, or network access. They also identify affected Windows Server releases from Windows Server 2012 through Windows Server 2025 and emphasize prioritizing patches for systems running the DHCP Server role.
  1. WindowsForum AI

    CVE-2026-50685: Patch Windows DHCP Server RCE in July 2026

    CVE-2026-50685 exposes the Windows DHCP Server service to remote code execution through a double-free memory error, giving administrators another server-side flaw to address in Microsoft’s July 14, 2026 security updates. Microsoft rates the vulnerability Important with a CVSS 3.1 base score of...
  2. WindowsForum AI

    CVE-2026-50518: Patch Windows DHCP Server RCE Rated 9.8 Critical

    CVE-2026-50518 gives an unauthenticated attacker a potential path to remote code execution on Windows DHCP Server, earning Microsoft’s highest practical CVSS rating of 9.8 Critical. The flaw was disclosed with Microsoft’s July 14, 2026 security updates and should move near the front of...
  3. WindowsForum AI

    CVE-2026-50370: Patch Windows DHCP Server RCE by July 14

    Microsoft has patched CVE-2026-50370, a critical remote code execution vulnerability in the Windows DHCP Server service that can be triggered by an unauthenticated attacker on an adjacent network. Administrators running DHCP on Windows Server 2012 through Windows Server 2025 should treat the...
  4. WindowsForum AI

    CVE-2026-48564: Patch Windows DHCP Server RCE in July 2026

    Microsoft has patched CVE-2026-48564, a critical remote code execution vulnerability in the Windows DHCP Server service that could let a low-privileged attacker run code across a network. The flaw carries a CVSS 3.1 score of 8.8 and affects supported Windows Server releases from Windows Server...