Skip to content

CVE-2026-69910

Windows Hyper-V stack-based buffer overflow enables remote code execution (CVE-2026-69910)

Critical 9.8 Vendor: Microsoft Published

A stack-based buffer overflow in Windows Hyper-V can be exploited over the network without authentication or user interaction. Microsoft has released fixed builds; apply the September 2026 update.

What happened

Microsoft has disclosed a stack-based buffer overflow (CWE-121) in Windows Hyper-V. The CVSS 3.1 vector describes an attack over the network with low complexity, no privileges for the attacker, and no user interaction. The impact on confidentiality, integrity, and availability is rated high. An unauthorised attacker able to reach the affected interface could execute code.

Microsoft rates the vulnerability Important, while the CVSS score is 9.8, critical. Exploit code maturity is rated unproven; Microsoft has not stated that the vulnerability has been publicly disclosed or exploited, and CISA KEV does not list it.

Who is affected

Microsoft lists affected Windows desktop and server platforms before the fixed builds shown below. The affected products include Windows 10 version 1607, 1809, 21H2, and 22H2; Windows 11 version 23H2, 24H2, 25H2, and 26H1; Windows Server 2016 and Windows Server 2016 (Server Core installation); and Windows Server 2019. Fixed versions are also published for Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2025, and Windows Server 2025 (Server Core installation).

What to do now

  1. Apply the September 2026 security update. The fixed builds are:
  • Windows 10 1607: 10.0.14393.9512 (KB5123099)
  • Windows 10 1809: 10.0.17763.9245 (KB5122876)
  • Windows 10 21H2/22H2: 10.0.19044.7725 and 10.0.19045.7725 (KB5122878)
  • Windows 11 23H2: 10.0.22631.7582 (KB5122880)
  • Windows 11 24H2/25H2: 10.0.26100.9445 and 10.0.26200.9445 (KB5124008)
  • Windows 11 26H1: 10.0.28000.2954 (KB5124012)
  • Windows Server 2016 and Core: 10.0.14393.9512 (KB5123099)
  • Windows Server 2019 and Core: 10.0.17763.9245 (KB5122876)
  • Windows Server 2022: 10.0.20348.5622 (KB5122882)
  • Windows Server 2025 and Core: 10.0.26100.33438 (KB5122871)
  1. Microsoft has not published a workaround for this CVE. If patching cannot be done immediately, restrict network exposure to Hyper-V hosts and remove access from untrusted networks.

Beyond the patch

For most organisations Hyper-V is the platform under core workloads, so patching has to be coordinated across a fleet rather than a single host. Because this flaw is reachable over the network without credentials, an exposed management service is the first thing to look for; Virtual CISO Services (vCISO) can help you find and reduce that exposure before the next advisory. If code execution does occur, Managed Detection & Response (MDR) is designed to catch the post-exploitation activity that follows.

Affected and fixed versions

ProductAffectedFixed in
Windows 10 Version 160710.0.14393.0 – < 10.0.14393.951210.0.14393.9512
Windows 10 Version 180910.0.17763.0 – < 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H210.0.19044.0 – < 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H210.0.19045.0 – < 10.0.19045.772510.0.19045.7725
Windows 11 version 23H210.0.22631.0 – < 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H210.0.22631.0 – < 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H210.0.26100.0 – < 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H210.0.26200.0 – < 10.0.26200.944510.0.26200.9445
Windows 11 version 26H110.0.28000.0 – < 10.0.28000.295410.0.28000.2954
Windows Server 201610.0.14393.0 – < 10.0.14393.951210.0.14393.9512
(Server Core installation) 10.0.14393.9512
Windows Server 2016 (Server Core installation)10.0.14393.0 – < 10.0.14393.951210.0.14393.9512
Windows Server 201910.0.17763.0 – < 10.0.17763.924510.0.17763.9245
(Server Core installation) 10.0.17763.9245

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.