CVE-2026-62718 is an integer underflow in Microsoft's DHCP server that warrants more attention than its medium severity and low EPSS score suggest. The vulnerability exists in option parsing logic—specifically in how the server handles length values when processing DHCP options, typically in relay agent information or option 82 handling. The adjacent network attack vector is being sold as a meaningful constraint, but in modern enterprise environments, that boundary has collapsed. Wireless access points, VPN concentrators, and BYOD onboarding networks place attackers in an adjacent relationship to DHCP services by default. Every contractor on guest WiFi, every remote worker, every compromised laptop running reconnaissance—these are the realistic threat actors, not someone physically tapped onto a VLAN. The EPSS probability is measuring historical adjacent-network exploit rates, not current enterprise topology reality. But the deeper problem isn't the attack surface—it's the source code. Microsoft DHCP servers have accumulated option handlers across three decades of Windows Server releases. When option parsing logic gets refactored, the old parsers aren't deleted; they're marked internal, stripped from documentation, and left in the binary as fallback paths for backward compatibility. That's where integer underflows breed—in deprecated code paths that nobody on the current team knows why they're there, tested by nobody, and reviewed by no one because DHCP code review gets assigned to whoever has bandwidth, not whoever has threat model expertise. The patch likely addresses this specific underflow, but the pattern historyrhyme identifies suggests more are lurking in adjacent option parsing paths. For defenders: treat this as a forcing function to inventory which DHCP option handling paths are actually live versus deprecated. If your DHCP server has been in production for more than three major OS versions, you're running buried legacy code that likely has similar issues. Prioritize patching, but also plan for a code audit—the next integer underflow in this same server is probably waiting in an adjacent deprecated handler, and the EPSS score measures whether it will be exploited after disclosure, not whether it already has been.
CVE-2026-62718
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedInteger underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
In the news
Third-party coverageSurfaced from public web coverage — external links open in a new tab.
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysisThe code reads past the end (or before the start) of a buffer, returning memory that was never meant to be exposed. Attackers use it to leak secrets like keys or to defeat memory-protection defences. Remediation is validating indices and lengths before every read.
General guidance for the out-of-bounds read class — the official description and references above are authoritative for this specific CVE. Want a bespoke review and a reviewed fix? Ask our team →
Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.
NVD · CPE data< 10.0.14393.9418< 10.0.17763.9115all versions= r2< 10.0.14393.9418< 10.0.17763.9115< 10.0.20348.5440< 10.0.26100.33222CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Adjacent
- Complexity
- Low
- Privileges
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- None
- Availability
- None
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
From vendor data10.0.14393.941810.0.17763.911510.0.20348.5440
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2026-62718 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sourcesCVE-2026-62718 is an integer underflow in Microsoft's DHCP server that warrants more attention than its medium severity and low EPSS score suggest. The vulnerability exists in option parsing logic—specifically in how the server handles length values when processing DHCP options, typically in relay agent information or option 82 handling. The adjacent network attack vector is being sold as a meaningful constraint, but in modern enterprise environments, that boundary has collapsed. Wireless access points, VPN concentrators, and BYOD onboarding networks place attackers in an adjacent relationship to DHCP services by default. Every contractor on guest WiFi, every remote worker, every compromised laptop running reconnaissance—these are the realistic threat actors, not someone physically tapped onto a VLAN. The EPSS probability is measuring historical adjacent-network exploit rates, not current enterprise topology reality. But the deeper problem isn't the attack surface—it's the source code. Microsoft DHCP servers have accumulated option handlers across three decades of Windows Server releases. When option parsing logic gets refactored, the old parsers aren't deleted; they're marked internal, stripped from documentation, and left in the binary as fallback paths for backward compatibility. That's where integer underflows breed—in deprecated code paths that nobody on the current team knows why they're there, tested by nobody, and reviewed by no one because DHCP code review gets assigned to whoever has bandwidth, not whoever has threat model expertise. The patch likely addresses this specific underflow, but the pattern historyrhyme identifies suggests more are lurking in adjacent option parsing paths. For defenders: treat this as a forcing function to inventory which DHCP option handling paths are actually live versus deprecated. If your DHCP server has been in production for more than three major OS versions, you're running buried legacy code that likely has similar issues. Prioritize patching, but also plan for a code audit—the next integer underflow in this same server is probably waiting in an adjacent deprecated handler, and the EPSS score measures whether it will be exploited after disclosure, not whether it already has been.
Practitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2026-62718 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data