
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32149 is an improper input validation vulnerability in Windows Hyper-V that allows an authorized local attacker to execute arbitrary code. Rooted in heap-based buffer overflow (CWE-122) and integer underflow (CWE-191) conditions, the flaw was disclosed and patched on April 14, 2026, as part of Microsoft's April 2026 Patch Tuesday. Affected products span a wide range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, 2022 23H2, and Windows Server 2025. The vulnerability carries a CVSS v3.1 base score of 7.3 (High) (MSRC Advisory, GitHub Advisory).
The vulnerability is classified under CWE-20 (Improper Input Validation), with underlying weaknesses of CWE-122 (Heap-based Buffer Overflow) and CWE-191 (Integer Underflow/Wraparound) in the Windows Hyper-V component. An attacker with low-privileged local access who can induce user interaction can supply maliciously crafted input that triggers the heap overflow or integer underflow, ultimately enabling arbitrary code execution. The attack vector is local (AV:L), requires low privileges (PR:L), and necessitates user interaction (UI:R), limiting remote exploitation but still posing significant risk in shared or multi-tenant virtualization environments (MSRC Advisory, GitHub Advisory).
Successful exploitation results in high impact to confidentiality, integrity, and availability of the affected system, potentially enabling complete system compromise. An attacker could execute arbitrary code in the context of the Hyper-V component, which may allow access to sensitive data, modification of system state, or disruption of virtualized workloads. Given Hyper-V's role as a hypervisor, exploitation could have implications for guest virtual machines running on the affected host, though the scope is marked as unchanged, suggesting the impact is contained to the vulnerable component (MSRC Advisory, GitHub Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (MSRC Advisory). The EPSS score is approximately 0.108–0.13%, placing it in roughly the 32nd percentile for exploitation likelihood within 30 days (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported. The requirement for local access and user interaction further reduces the practical exploitability compared to remote, unauthenticated vulnerabilities.
Microsoft released patches on April 14, 2026, as part of the April 2026 Patch Tuesday update cycle. Organizations should apply the following minimum patched build versions: Windows 10 1607 / Server 2016 (10.0.14393.9060+), Windows 10 1809 / Server 2019 (10.0.17763.8644+), Windows 10 21H2 (10.0.19044.7184+), Windows 10 22H2 (10.0.19045.7184+), Windows Server 2022 (10.0.20348.5020+), Windows Server 2022 23H2 (10.0.25398.2274+), Windows 11 23H2 (10.0.22631.6936+), Windows 11 24H2 / Server 2025 (10.0.26100.8246+ / 10.0.26100.32690+), Windows 11 25H2 (10.0.26200.8246+), and Windows 11 26H1 (10.0.28000.1836+). As a complementary measure, restrict local user access on Hyper-V hosts and monitor for suspicious Hyper-V-related activity (MSRC Advisory).
The vulnerability was covered as part of broader April 2026 Patch Tuesday reporting, which addressed 167 flaws in total. Security outlets including BleepingComputer, Rapid7, Zero Day Initiative (ZDI), and CyberSecurityNews covered the patch release, though CVE-2026-32149 was not individually highlighted as a top-priority item given the absence of active exploitation (BleepingComputer, ZDI Blog, Rapid7 Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."