Skip to content
Rush Commerce
Field Notes3 min read

Windows DNS RCE CVE-2026-62878: CVSS 9.8, no login

August Patch Tuesday shipped 421 CVEs including a 9.8 unauthenticated RCE in Windows DNS Server. If you run your own DNS, this one jumps the queue.

August Patch Tuesday was one of the largest on record — 421 CVEs in a single drop. Buried in that pile is CVE-2026-62878, a CVSS 9.8 remote code execution flaw in Windows DNS Server that needs no credentials and no user interaction. If you run a Windows DNS server that answers queries from outside your network, stop reading the rest of the list and patch that box first.

What actually happened

Microsoft shipped fixes for 421 vulnerabilities on August 11, 2026, per Rapid7's breakdown — Windows accounted for 236, with the rest spread across Office, SharePoint, Azure, Exchange, and developer tools.

CVE-2026-62878 is a stack-based buffer overflow in Windows DNS Server that leads to remote code execution, as Help Net Security described it. The relevant properties:

  • CVSS 9.8, remote, unauthenticated, no user interaction required
  • Microsoft's own exploitability rating is "Exploitation Less Likely" — a judgment about difficulty, not about impact
  • Security researchers have flagged it as potentially wormable given the lack of auth prerequisites. Microsoft has not applied that label itself, so treat "wormable" as an analyst read, not a vendor statement

It is not the only unauthenticated RCE in this batch. CVE-2026-62815 in Microsoft QUIC also allows code execution from a crafted packet with no authentication or user interaction. And this is the same Patch Tuesday that carried the actively exploited AFD zero-day, CVE-2026-68820, plus the SharePoint RCE chain.

Why an unauthenticated DNS flaw matters for your business

Most small businesses will read "421 CVEs" and do nothing, because 421 is not a number you can act on. So reduce it. Two questions decide your whole month:

Do we run our own DNS server, and does anything outside our network talk to it? If yes, CVE-2026-62878 is your top priority this week. A pre-auth RCE on a DNS server is worse than the CVSS suggests, because DNS is the thing every other system trusts to tell it where to go. Own the resolver, own the traffic. We covered what DNS manipulation buys an attacker — it is not a niche attack path.

If we don't, who does? Plenty of small shops run DNS through a managed provider or their registrar and genuinely do not have this exposure. That is a legitimate answer, but confirm it rather than assume it. The Windows Server sitting in a closet running Active Directory is very often also a DNS server, and nobody remembers that until it matters.

Then patch by exploitation status, not by severity count. We have made this argument before: the actively exploited zero-day and the CISA KEV deadline come first, then the pre-auth RCEs on internet-facing services, then everything else on your normal cycle. A 421-CVE month is unmanageable as a list and completely manageable as three buckets.

Write the buckets down once. You will use them again next month.

Key takeaways

  • August 2026 Patch Tuesday shipped 421 CVEs — one of the largest totals Microsoft has ever released at once
  • CVE-2026-62878 is a CVSS 9.8 stack-based buffer overflow in Windows DNS Server: remote, unauthenticated, no user interaction
  • Microsoft rates exploitation "Less Likely"; the wormable framing comes from researchers, not from Microsoft
  • CVE-2026-62815 (Microsoft QUIC) is a second unauthenticated RCE in the same batch
  • Answer one question first: do you run a Windows DNS server reachable from outside? If yes, patch it before anything else on the list

Not sure what you actually expose to the internet? We inventory the systems a small business really runs and set a patch order you can follow without a security team. Get a straight answer on your exposure or see how we build it.

Sources: Rapid7, Help Net Security.

  • #cve-2026-62878
  • #patch-tuesday
  • #windows-dns
  • #rce
  • #patch-management
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.