Vulnary
← back to the feed
Critical· 9.8

CVE-2026-56159

A heap-based buffer overflow in the Windows DHCP Server lets an unauthenticated attacker run arbitrary code over the network. The flaw is rated critical with a CVSS score of 9.8 and affects multiple Windows 10 and Windows Server releases. No official patch, known exploitation, or public exploit is documented in the provided sources.

publishedJul 14, 2026
last modifiedJul 21, 2026
sourcesNVD
severity · cvss
9.8
critical · how bad it is
exploitation · epss
<1%
59th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 4, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Microsoft Windows 10 versions 1607 and 1809; Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025.

02

Real-world impact

An attacker could exploit this remotely to execute code with the privileges of the DHCP service, potentially leading to full system compromise.

03

Why this severity

CVSS v3.8. Attack Vector: Attack Complexity: Low, Privileges Required: None, User Interaction: None, Scope: Unchanged, Confidentiality: High, Integrity: High, Availability: High).

04

What to do about it

no official fix yet

No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.

No fix documented in sources

05

Timeline

  1. Jul 14, 2026 · 20d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 21, 2026 · 13d ago
    Advisory updated
    The NVD record was last revised.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
CVE-2026-56159: A heap-based buffer overflow in the Windows DHCP Server lets an unauth · Vulnary