CVE-2026-69603 – Windows Hyper-V Remote Code Execution Vulnerability

CVSS 8.8 IMPORTANT Critical - Same Day Deployment

“A malicious hypercall can turn a memory flaw in Hyper-V into high-impact code execution across a security boundary.”

CVE-2026-69603 is a critical heap-based buffer overflow vulnerability in Windows Hyper-V. An authorized attacker running code inside a virtualized environment can issue a specially crafted hypercall containing a maliciously large or malformed payload size. This can trigger a buffer overflow in the hypervisor during memory operations and allow local code execution. The vulnerability requires low privileges and no user interaction.

Key Details

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-122
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.