CVE-2026-69910
Windows Hyper-V stack-based buffer overflow enables remote code execution (CVE-2026-69910)
A stack-based buffer overflow in Windows Hyper-V can be exploited over the network without authentication or user interaction. Microsoft has released fixed builds; apply the September 2026 update.
What happened
Microsoft has disclosed a stack-based buffer overflow (CWE-121) in Windows Hyper-V. The CVSS 3.1 vector describes an attack over the network with low complexity, no privileges for the attacker, and no user interaction. The impact on confidentiality, integrity, and availability is rated high. An unauthorised attacker able to reach the affected interface could execute code.
Microsoft rates the vulnerability Important, while the CVSS score is 9.8, critical. Exploit code maturity is rated unproven; Microsoft has not stated that the vulnerability has been publicly disclosed or exploited, and CISA KEV does not list it.
Who is affected
Microsoft lists affected Windows desktop and server platforms before the fixed builds shown below. The affected products include Windows 10 version 1607, 1809, 21H2, and 22H2; Windows 11 version 23H2, 24H2, 25H2, and 26H1; Windows Server 2016 and Windows Server 2016 (Server Core installation); and Windows Server 2019. Fixed versions are also published for Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2025, and Windows Server 2025 (Server Core installation).
What to do now
- Apply the September 2026 security update. The fixed builds are:
- Windows 10 1607: 10.0.14393.9512 (KB5123099)
- Windows 10 1809: 10.0.17763.9245 (KB5122876)
- Windows 10 21H2/22H2: 10.0.19044.7725 and 10.0.19045.7725 (KB5122878)
- Windows 11 23H2: 10.0.22631.7582 (KB5122880)
- Windows 11 24H2/25H2: 10.0.26100.9445 and 10.0.26200.9445 (KB5124008)
- Windows 11 26H1: 10.0.28000.2954 (KB5124012)
- Windows Server 2016 and Core: 10.0.14393.9512 (KB5123099)
- Windows Server 2019 and Core: 10.0.17763.9245 (KB5122876)
- Windows Server 2022: 10.0.20348.5622 (KB5122882)
- Windows Server 2025 and Core: 10.0.26100.33438 (KB5122871)
- Microsoft has not published a workaround for this CVE. If patching cannot be done immediately, restrict network exposure to Hyper-V hosts and remove access from untrusted networks.
Beyond the patch
For most organisations Hyper-V is the platform under core workloads, so patching has to be coordinated across a fleet rather than a single host. Because this flaw is reachable over the network without credentials, an exposed management service is the first thing to look for; Virtual CISO Services (vCISO) can help you find and reduce that exposure before the next advisory. If code execution does occur, Managed Detection & Response (MDR) is designed to catch the post-exploitation activity that follows.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Windows 10 Version 1607 | 10.0.14393.0 – < 10.0.14393.9512 | 10.0.14393.9512 |
| Windows 10 Version 1809 | 10.0.17763.0 – < 10.0.17763.9245 | 10.0.17763.9245 |
| Windows 10 Version 21H2 | 10.0.19044.0 – < 10.0.19044.7725 | 10.0.19044.7725 |
| Windows 10 Version 22H2 | 10.0.19045.0 – < 10.0.19045.7725 | 10.0.19045.7725 |
| Windows 11 version 23H2 | 10.0.22631.0 – < 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 23H2 | 10.0.22631.0 – < 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 24H2 | 10.0.26100.0 – < 10.0.26100.9445 | 10.0.26100.9445 |
| Windows 11 Version 25H2 | 10.0.26200.0 – < 10.0.26200.9445 | 10.0.26200.9445 |
| Windows 11 version 26H1 | 10.0.28000.0 – < 10.0.28000.2954 | 10.0.28000.2954 |
| Windows Server 2016 | 10.0.14393.0 – < 10.0.14393.9512 | 10.0.14393.9512 (Server Core installation) 10.0.14393.9512 |
| Windows Server 2016 (Server Core installation) | 10.0.14393.0 – < 10.0.14393.9512 | 10.0.14393.9512 |
| Windows Server 2019 | 10.0.17763.0 – < 10.0.17763.9245 | 10.0.17763.9245 (Server Core installation) 10.0.17763.9245 |