PatchDay Alert

CVE

CVE-2026-41096

0field notes · 1digest CVSS 9.8


Daily digests

An unauthenticated attacker can trigger a heap-based buffer overflow in the Windows DNS service and execute code remotely. No credentials needed, no user interaction. CVSS 9.8. If your DNS servers face the network (and they do), this is a top-priority patch.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.