a 9.9 in Windows Hyper-V lets an attacker break out of one VM and take the whole host's network

CVE-2026-57092 is a use-after-free in Windows VMSwitch — the virtual network switch behind Hyper-V. It scores 9.9 because it breaks out of its…

Aliteq
Priya Nair · Software & Systems Editor

What you need to know

The flaw: a use-after-free (CWE-416) in Windows VMSwitch, Hyper-V's virtual network switch.

What you need to know

Impact: a low-privileged attacker elevates privileges across the virtualization boundary (Scope: Changed → the 9.9).

What you need to know

Affected: Windows 10, Windows 11, and Windows Server 2012 through 2025.

What you need to know

Requires a low-privileged authenticated foothold — but that's routine for an attacker already inside a VM.

What you need to know

Fix: the July 2026 security update. Prioritise Hyper-V hosts and multi-tenant environments.

Aliteq

Read the full story

a 9.9 in Windows Hyper-V lets an attacker break out of one VM and take the whole host's network

Read the full story on Aliteq