CVE-2026-69910
massUnauthenticated Network RCE via Stack Buffer Overflow in Windows Hyper-V
CVE-2026-69910 is a critical stack-based buffer overflow (CWE-121) in Windows Hyper-V that Microsoft rates 9.8 on the CVSS 3.1 scale. It is triggered when an unauthenticated remote attacker sends crafted input over a network to a vulnerable Hyper-V component, overflowing a stack-based buffer. Successful exploitation could allow the attacker to execute arbitrary code with high impact on confidentiality, integrity, and availability (per the CVSS scope). Any Windows deployment with Hyper-V enabled is potentially affected; the available data does not specify affected version ranges, so defenders should consult Microsoft's advisory. There is no public proof-of-concept, the flaw is not yet in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at about 1%, indicating no known exploitation to date.
What to do: Apply Microsoft's security update for CVE-2026-69910 via Windows Update/WSUS as soon as it is released, prioritizing multi-tenant and network-exposed Hyper-V hosts. As an interim measure, restrict network access to Hyper-V hosts and limit untrusted guest-to-host and external network paths. Inventory which servers and workstations have the Hyper-V role/feature enabled and monitor Microsoft's advisory for the confirmed affected version ranges.
| Microsoft Windows Hyper-V | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.