CVE-2026-49169: Microsoft Windows Server 2025
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
Use after free in DNS Server allows an authorized attacker to execute code over a network.
Affected products
- Microsoft Windows Server 2025: before 10.0.26100.33158 (fixed in 10.0.26100.33158)
Published 2026-07-14. Last modified 2026-07-16.