Windows Hyper-V Remote Code Execution Vulnerability
Plan PatchCVSS 9.8CVE-2026-69910Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Stack-based buffer overflow in Windows Hyper-V allows unauthorized network-based attacker to execute code. An attacker with network access to a Hyper-V service can send a specially crafted request to trigger the buffer overflow, leading to arbitrary code execution with system-level privileges. This affects Windows Server 2016, 2019, 2022, 2025 and Windows 10/11 systems with Hyper-V enabled.
What this means
What could happen
A stack-based buffer overflow in Windows Hyper-V could allow an attacker on your network to run arbitrary code on affected servers with system-level privileges, potentially compromising all virtual machines and workloads running on those hosts.
Who's at risk
This affects any organization running Windows Server 2016, 2019, 2022, or 2025 with Hyper-V enabled, as well as Windows 10 and Windows 11 systems that use Hyper-V for virtualization. Water utilities and municipal electric authorities using Windows Server for SCADA systems, process management databases, or virtual infrastructure should prioritize patching. This is particularly critical if these servers host virtualized PLCs, historian databases, or operator workstations.
How it could be exploited
An attacker with network access to a Windows Server running Hyper-V could send a specially crafted network request to trigger a buffer overflow in the Hyper-V network stack, leading to remote code execution. The attacker would need to reach the Hyper-V service port on the target server directly.
Prerequisites
- Network access to Windows Server running Hyper-V
- Hyper-V service enabled and accessible from the network
- No authentication required
Remotely exploitableNo authentication requiredLow attack complexityCritical severity (CVSS 9.8)Affects virtualization platform
Exploitability
Unlikely to be exploited — EPSS score 1.0%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/9
Do now
0/1WORKAROUNDRestrict network access to Hyper-V management ports using firewall rules to allow only trusted administrative workstations
Schedule — requires maintenance window
0/8Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33438 or later
All products
HOTFIXUpdate Windows 10 Version 1809 (32-bit) to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 1809 (x64) to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 21H2 to Build 10.0.19044.7725 or later
HOTFIXUpdate Windows 10 Version 22H2 to Build 10.0.19045.7725 or later
HOTFIXUpdate Windows 11 (all versions) to the September 2026 security update or later
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/7221b6f9-64cb-4ae3-9610-3f65d5dcd3d5Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.