ZeroHour

CVE-2026-69910

mass

Unauthenticated Network RCE via Stack Buffer Overflow in Windows Hyper-V

CVSS 3.1
9.8 critical
EPSS
<1%p61
Published
()
Modified
AI analysis

CVE-2026-69910 is a critical stack-based buffer overflow (CWE-121) in Windows Hyper-V that Microsoft rates 9.8 on the CVSS 3.1 scale. It is triggered when an unauthenticated remote attacker sends crafted input over a network to a vulnerable Hyper-V component, overflowing a stack-based buffer. Successful exploitation could allow the attacker to execute arbitrary code with high impact on confidentiality, integrity, and availability (per the CVSS scope). Any Windows deployment with Hyper-V enabled is potentially affected; the available data does not specify affected version ranges, so defenders should consult Microsoft's advisory. There is no public proof-of-concept, the flaw is not yet in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at about 1%, indicating no known exploitation to date.

What to do: Apply Microsoft's security update for CVE-2026-69910 via Windows Update/WSUS as soon as it is released, prioritizing multi-tenant and network-exposed Hyper-V hosts. As an interim measure, restrict network access to Hyper-V hosts and limit untrusted guest-to-host and external network paths. Inventory which servers and workstations have the Hyper-V role/feature enabled and monitor Microsoft's advisory for the confirmed affected version ranges.

Affected
Microsoft Windows Hyper-V
Estimated exposure
masspotentially millions of hosts (Hyper-V is built into Windows Server and Windows Pro/Enterprise SKUs) — Hyper-V ships as an integrated component of Windows Server and Windows Pro/Enterprise client editions, whose installed bases run to tens of millions and hundreds of millions of systems respectively, though actual exposure is limited to…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.

Weakness
CWE-121
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.