
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21247 is an improper input validation vulnerability in Windows Hyper-V that allows an authorized local attacker to execute arbitrary code. It was disclosed and patched on February 10, 2026, as part of Microsoft's February 2026 Patch Tuesday security updates. Affected products span a wide range of Windows versions including Windows 10 (21H2, 22H2, 1607, 1809), Windows 11 (23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, 2022 23H2, and 2025. The vulnerability carries a CVSS v3.1 base score of 7.3 (High) (Microsoft MSRC).
The root cause is improper input validation (CWE-20) in the Windows Hyper-V hypervisor component, which leads to both heap-based buffer overflow (CWE-122) and out-of-bounds read (CWE-125) conditions. An attacker with low-privileged local access who can induce user interaction can supply maliciously crafted input to trigger these memory corruption conditions and achieve code execution. The attack vector is local (AV:L), requires low privileges (PR:L), and necessitates user interaction (UI:R), limiting remote exploitation but still posing a significant risk in shared or multi-tenant virtualization environments (Microsoft MSRC).
Successful exploitation results in complete compromise of the affected Hyper-V system, with high impact to confidentiality, integrity, and availability. An attacker could execute arbitrary code in the context of the Hyper-V service, potentially enabling access to sensitive data, modification of system state, or disruption of virtualized workloads. In environments where Hyper-V hosts multiple virtual machines, exploitation could have cascading effects on hosted guest systems (Microsoft MSRC).
Microsoft released patches on February 10, 2026, addressing this vulnerability across all affected Windows versions. Administrators should apply the February 2026 cumulative updates to bring systems to the following minimum build versions: Windows Server 2025 (10.0.26100.32313), Windows Server 2022 (10.0.20348.4711), Windows Server 2022 23H2 (10.0.25398.2149), Windows Server 2019 (10.0.17763.8389), Windows Server 2016 (10.0.14393.8868), Windows 11 24H2 (10.0.26100.7781), Windows 11 25H2 (10.0.26200.7781), Windows 11 23H2 (10.0.22631.6649), Windows 10 22H2 (10.0.19045.6937), Windows 10 21H2 (10.0.19044.6937), and Windows 10 1809/1607 (10.0.17763.8389 / 10.0.14393.8868). As a defense-in-depth measure, restrict local access to Hyper-V hosts to only authorized administrators and monitor for unusual process activity originating from Hyper-V services (Microsoft MSRC).
The vulnerability was covered as part of broader February 2026 Patch Tuesday roundups by security vendors and researchers. Qualys, Rapid7, Sophos, and BleepingComputer all included CVE-2026-21247 in their Patch Tuesday analyses, noting it as a notable Hyper-V code execution flaw among the 58 vulnerabilities addressed that month (Qualys Blog, BleepingComputer, Sophos Blog). NSFOCUS also flagged it in their high-risk vulnerability notice for Microsoft's February 2026 updates (NSFOCUS). General community sentiment treated it as a medium-high priority patch given the Hyper-V attack surface, though the local-only attack vector tempered urgency compared to remote code execution flaws patched in the same cycle.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."