Apply Microsoft's August 2026 security updates promptly. Prioritize patching of Windows DNS Server components, especially on internet-facing systems. Monitor Microsoft security advisories for additional details and verification of the vulnerability specifics. Implement network segmentation and access controls for DNS server roles as defense-in-depth measures while awaiting patch deployment.
Quick answers
What is CVE-2026-62878?
Apply Microsoft's August 2026 security updates promptly. Prioritize patching of Windows DNS Server components, especially on internet-facing systems. Monitor Microsoft security advisories for additional details and verification of the vulnerability specifics. Implement network segmentation and access controls for DNS server roles as defense-in-depth measures while awaiting patch deployment.
How severe is CVE-2026-62878?
critical, CVSS 9.8
Is CVE-2026-62878 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-62878 be mitigated?
Apply Microsoft's August 2026 security updates promptly. Prioritize patching of Windows DNS Server components, especially on internet-facing systems. Monitor Microsoft security advisories for additional details and verification of the vulnerability specifics. Implement network segmentation and access controls for DNS server roles as defense-in-depth measures while awaiting patch deployment.
CVSS
9.8
Vendor
Microsoft
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Windows
Mitigation
Apply Microsoft's August 2026 security updates promptly. Prioritize patching of Windows DNS Server components, especially on internet-facing systems. Monitor Microsoft security advisories for additional details and verification of the vulnerability specifics. Implement network segmentation and access controls for DNS server roles as defense-in-depth measures while awaiting patch deployment.
Microsoft's August 2026 Patch Tuesday update includes a critical remote code execution vulnerability in the Windows DNS Server component, tracked as CVE-2026-62878 with a CVSS score of 9.8. The vulnerability requires no user interaction and could allow remote code execution on internet-facing DNS servers. The update bundle also addresses additional security flaws across Windows and related components.