CVE-2026-21248Disclosure(microsoft / windows_10_1607)

MEDIUMCVSS 7.3 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for microsoft windows_10_1607 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-787

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-10); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_server_2016windows_server_2019windows_server_2022

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-02-10: 2Mentions · 2026-02-15: 2Mentions · 2026-06-07: 1PoC Mentioned / Linked · 2026-02-15: 1PoC Mentioned / Linked · 2026-06-07: 1Exploit Tool / Code · 2026-02-15: 1Exploit Tool / Code · 2026-06-07: 1Technical Details · 2026-02-10: 1Technical Details · 2026-02-15: 2Technical Details · 2026-06-07: 102-1002-1506-07
Signal classification2 categories
Disclosure
360.0%
Exploit
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-102
Disclosure2
2026-02-152
Disclosure1Exploit1
2026-06-071
Exploit1
Full discourse5 posts
  • NSA Agent #777@biopunk0
    Exploit

    @encrypted_past CVE-2026-21248 - Windows Hyper-V Ghost Patch Exploit Framework Author: nu11secur1ty Date: 2026-02-13 Target: Windows 11 25H2 Build 26200.7830 (x64) WSL may be another PoC

    Post summary

    The post announces a Windows Hyper‑V vulnerability (CVE‑2026‑21248) that has an associated exploit framework, with a possible PoC via WSL, but provides no evidence of active exploitation or patch availability.

    010101.8K
    169 followersView on X
  • AgniOps@AgniOpsIn
    Disclosure

    🔥 Windows Hyper-V | CVE-2026-21248 A heap overflow in Hyper-V can allow privilege escalation on the host, impacting all guest VMs. Deep technical analysis 👇 https://www.agniops.in/post/windows-11-25h2-hyper-v-cve-2026-21248-heap-overflow-ghost-patch-exploit-framework #WindowsSecurity #HyperV #CVE #Virtualization #ThreatResearch

    Post summary

    The post announces CVE‑2026‑21248, a heap overflow in Windows Hyper‑V that permits host privilege escalation, and links to a detailed technical analysis.

    01010103
    1 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting Microsoft Windows (CVE-2026-21248) https://vuldb.com/?id.345274

    Post summary

    The text announces a new Windows vulnerability, CVE-2026-21248, and notes its severity has increased, but offers no further technical or patch details.

    0001071
    2.1K followersView on X
  • nu11secur1ty@nu11secur1ty1
    Exploit

    Windows 11 25H2 Hyper-V CVE-2026-21248 Heap Overflow + Ghost Patch Exploit Framework - http://CXSecurity.com https://cxsecurity.com/issue/WLB-2026020011

    Post summary

    The post announces a Windows 11 25H2 Hyper‑V CVE-2026-21248 Heap Overflow exploit framework, linking to a CXSecurity page that likely contains PoC code.

    0000087
    105 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21248 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. https://www.cve.org/CVERecord?id=CVE-2026-21248

    Post summary

    A heap-based buffer overflow in Windows Hyper‑V that allows local code execution has been disclosed.

    00000172
    56.5K followersView on X
CPE platform detail15 entries

15 of 15 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more