
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21244 is a heap-based buffer overflow vulnerability in Windows Hyper-V that allows an authorized attacker with low privileges to execute arbitrary code locally. It was disclosed and patched on February 10, 2026, as part of Microsoft's February 2026 Patch Tuesday security update. Affected products span a wide range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022 (including 23H2), and Windows Server 2025. The vulnerability carries a CVSS v3.1 base score of 7.3 (High) (Microsoft MSRC).
The vulnerability is classified under CWE-122 (Heap-based Buffer Overflow) and CWE-787 (Out-of-bounds Write), and is associated with CAPEC-92 (Forced Integer Overflow). An authorized local attacker with low privileges can trigger an out-of-bounds write operation in the Windows Hyper-V component, leading to arbitrary code execution. Exploitation requires user interaction (UI:R) and operates within an unchanged scope, meaning the impact is confined to the vulnerable component. An exploit was published to Exploit-DB (entry 52537) in May 2026, indicating public availability of exploitation code (Microsoft MSRC, Feedly).
Successful exploitation results in high impact to confidentiality, integrity, and availability on the affected system. An attacker who exploits this vulnerability can execute arbitrary code within the context of the Hyper-V environment, potentially compromising guest or host system security, accessing sensitive data, and disrupting virtualized workloads. Given Hyper-V's role in server virtualization infrastructure, exploitation could have cascading effects across virtual machines hosted on the affected system (Microsoft MSRC).
vmwp.exe, vmms.exe); unusual process creation events associated with low-privileged user accounts on Hyper-V hosts.Microsoft released patches on February 10, 2026, as part of the February 2026 Patch Tuesday update. Administrators should update to the following minimum build versions: Windows 10 1607 (10.0.14393.8868), Windows 10 1809/Windows Server 2019 (10.0.17763.8389), Windows 10 21H2 (10.0.19044.6937), Windows 10 22H2 (10.0.19045.6937), Windows 11 23H2 (10.0.22631.6649), Windows 11 24H2 (10.0.26100.7781), Windows 11 25H2 (10.0.26200.7781), Windows Server 2022 (10.0.20348.4711), Windows Server 2022 23H2 (10.0.25398.2149), and Windows Server 2025 (10.0.26100.32313). As interim mitigations, restrict local access to Hyper-V hosts, enforce the principle of least privilege, and monitor for suspicious activity on virtualization infrastructure (Microsoft MSRC).
The vulnerability was covered as part of broader February 2026 Patch Tuesday roundups by multiple security vendors and researchers. Qualys, Rapid7, Talos Intelligence, Sophos, and BleepingComputer all included CVE-2026-21244 in their Patch Tuesday analyses, noting it as one of 58 vulnerabilities addressed that month. Coverage generally characterized it as a notable but not immediately critical issue given the local attack vector and user interaction requirement, with patching recommended as a priority for Hyper-V environments (Qualys Blog, Rapid7 Blog, Talos Blog, BleepingComputer).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."