CVE-2026-45602
CVE-2026-45602 is a critical flaw in Windows DHCP Server that lets an attacker tamper with the server over a network without needing credentials or user interaction. The vulnerability can be exploited by anyone on the same network, potentially allowing the attacker to alter DHCP responses or disrupt network services. It affects multiple Windows 10 and 11 builds as well as Windows Server 2012.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server 2012 running DHCP Server.
Real-world impact
An attacker could modify DHCP server behavior, redirecting clients to malicious sites, causing denial of service, or injecting harmful traffic into the network.
Why this severity
The CVSS score of 9.1 reflects that the flaw is exploitable over the network, requires no authentication or user interaction, and can compromise confidentiality and integrity of network traffic, making it a high‑risk vulnerability.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jun 9, 2026 · Jun 9, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 14d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- msrc.microsoft.com/update-guide/vulnerability/…vendor advisory