SYS::ONLINE
Wasteland.
Briefs1674
Issues21
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-45602 2026-06-09

CVE-2026-45602: Critical Windows DHCP Server Tampering Flaw

"A critical network-exploitable tampering vulnerability in Microsoft's Windows DHCP Server lets an unauthorized attacker compromise the confidentiality and integrity of affected systems over the network."

A critical network-exploitable tampering vulnerability in Microsoft's Windows DHCP Server lets an unauthorized attacker compromise the confidentiality and integrity of affected systems over the network.

What Is It

CVE-2026-45602 is a critical vulnerability in Windows DHCP Server that allows an unauthorized attacker to perform tampering over a network. It carries a CVSS 3.1 base score of 9.1 (Critical) with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. In plain terms, the flaw is exploitable remotely over the network, requires low attack complexity, needs no privileges, and requires no user interaction. Successful exploitation has a high impact on both confidentiality and integrity, with no measured impact on availability. The issue was disclosed by Microsoft (source identifier [email protected]) and published on June 9, 2026.

Why It Matters

DHCP servers are core network infrastructure that hand out IP addressing to clients across an environment. A flaw that is reachable over the network with no authentication and no user interaction is attractive to attackers because there is no barrier to attempt exploitation. The high confidentiality and integrity impacts mean an attacker could read sensitive data and tamper with information the server handles. As of this writing there is no CISA KEV entry, so active exploitation has not been confirmed in the supplied data, but the maximum exploitability score (3.9) means the attack surface is wide open.

What's Vulnerable

The supplied NVD record identifies the affected product as Windows DHCP Server. No specific affected version ranges or CPE configurations are listed in the supplied data, as the CVE is still Undergoing Analysis (NVD status). Refer to Microsoft's advisory for the authoritative list of affected builds.

Patch Status

The NVD record was last modified on June 9, 2026, and remains in "Undergoing Analysis" status. Microsoft has published an entry in its Security Update Guide for this CVE; administrators should consult that advisory for fixed builds and apply the available updates. No CISA-mandated remediation action is present in the supplied data.

Sources