PatchDay Alert

CVE

CVE-2026-40402

0field notes · 1digest CVSS 9.3


Daily digests

A use-after-free bug in Windows Hyper-V lets an unauthenticated local attacker escalate privileges. CVSS 9.3 is unusually high for a local bug, which likely means a guest-to-host escape. If you run Hyper-V, a compromised VM could break out and own the host.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.