Overview
What is CVE-2026-40402?
Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.
Vulnerability intelligence
CVE-2026-40402 and is rated Critical severity with a CVSS score of 9.3. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.