CVE-2026-40402Patch(microsoft / windows_11_23h2)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft windows_11_23h2 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_11_23h2
  • windows_server_2022

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-13); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
windows_11_23h2windows_server_2022

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-05-12: 1Mentions · 2026-05-13: 3Mentions · 2026-05-30: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-13: 3Patch / Workaround · 2026-05-30: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-13: 3Technical Details · 2026-05-30: 105-1205-1305-30
Signal classification2 categories
Patch
360.0%
Disclosure
240.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-121
Patch1
2026-05-133
Disclosure1Patch2
2026-05-301
Disclosure1
Full discourse5 posts
  • Juan Carlos Ortiz 🛡️ Ciberseguridad para Empresas@CycuraMX
    Patch

    🛡️Llegaron las actualizaciones de Windows Microsoft corrigió 138 vulnerabilidades en Windows, Office, Edge, Azure, Teams, Dynamics y otros productos. Las más urgentes para muchas empresas son: CVE-2026-41096, en Windows DNS. DNS traduce nombres como “empresa punto com” a direcciones que entienden los sistemas. Esta falla podría permitir ejecutar código remoto sin autenticación. CVE-2026-41089, en Windows Netlogon. Netlogon ayuda a validar usuarios en servidores de dominio. Si se explota, un atacante podría ejecutar código contra un controlador de dominio. CVE-2026-42898, en Dynamics 365 local. Dynamics administra ventas, clientes y operaciones. Esta falla puede convertir una aplicación de negocio en punto de ejecución remota. CVE-2026-41103, en el plugin SSO para Jira y Confluence. SSO permite entrar con una sola identidad. Esta falla podría permitir suplantar usuarios válidos. CVE-2026-40402, en Hyper-V. Hyper-V permite correr servidores virtuales. Esta falla podría dar privilegios altos sobre el ambiente de virtualización. Microsoft también pidió actualizar certificados de Secure Boot antes del 26 de junio de 2026. Secure Boot valida que el equipo arranque con componentes confiables.

    Post summary

    Microsoft announced patches for 138 CVEs, including several high‑impact Windows, Dynamics 365, and Hyper‑V flaws that could allow remote code execution or privilege escalation, with no mention of active exploitation or PoC exposures.

    01203042.5K
    7.7K followersView on X
  • كاسبر سكاي@KasperskyDev
    Disclosure

    ⚠️ ثغرة رفع صلاحيات حرجة تتيح لجهاز ضيف الخروج إلى المضيف الافتراضي والسيطرة عليه المعرّف : CVE-2026-40402 درجة الخطورة : 9.3 (CVSS) - Critical المنتج المتأثر : Windows Hyper-V الحل : May 2026 Patch Tuesday update #CVE #HyperV #Virtualization #CyberSecurity

    Post summary

    A new critical privilege‑escalation vulnerability (CVE‑2026‑40402) affecting Windows Hyper‑V is disclosed, with a patch slated for the upcoming May 2026 Patch Tuesday.

    01000155
    40.0K followersView on X
  • nico@nicolatech_
    Patch

    Microsoft publicó ayer su Patch Tuesday de mayo. 137 vulnerabilidades, 31 críticas. La que asusta: CVE-2026-41096, un RCE en el cliente DNS de Windows con score 9.8. Sin autenticación, sin interacción del usuario. Un atacante en red manda una respuesta DNS maliciosa y ejecuta código arbitrario vía heap buffer overflow. Cualquier Windows que resuelva DNS (o sea, todos) está expuesto hasta que parchee. También cayeron una Netlogon RCE potencialmente wormable (CVE-2026-41089) y una fuga Hyper-V guest-to-host (CVE-2026-40402). https://www.theregister.com/patches/2026/05/13/doozy-of-a-patch-tuesday-includes-30-critical-microsoft-cves/5239224

    Post summary

    The article announces Microsoft’s Patch Tuesday, highlights a critical RCE (CVE-2026-41096) with detailed technical information, and confirms a patch is available, but does not discuss PoCs or active exploitation.

    00010188
    103 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    🚨 CVE-2026-40402 (Windows Hyper-V, CVSS 9.0): UAF → guest VM escapes to HOST at ring -1. Own one VM → read ALL co-tenant data + mass-encrypt every virtual disk. Affects Server 2016–2025 & Win 10/11. Patch dropped 24h ago. Hyper-V admins: update NOW. #ZeroDay #HyperV

    Post summary

    CVE‑2026‑40402 is a high‑severity Windows Hyper‑V UAF vulnerability that lets a guest VM escape to host, reading or encrypting co‑tenant data; a patch has been released and admins are urged to apply it immediately.

    00000128
    210 followersView on X
  • WindowsForum@windowsforum
    Patch

    🪟 CVE-2026-40402: Hyper-V guest-to-host UAF that turns “virtual” into “privilege party.” Patch matters because if a VM can get SYSTEM on the host, your boundary is fake. https://windowsforum.com/threads/cve-2026-40402-critical-hyper-v-guest-to-host-privilege-escalation-risk-may-patch-tuesday.417975/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #PrivilegeEscalation #UseAfterFree #WindowsCve #HyperVSecurity https://t.co/s1xeauroBV

    Post summary

    The post highlights a new Hyper‑V guest‑to‑host use‑after‑free flaw that could elevate a VM’s privileges to SYSTEM, stressing that a patch is required to mitigate the risk.

    0000048
    1.1K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_server_2022---

Explore more