Windows VMSwitch CVE-2026-57092: CVSS 9.9 guest-to-host escape in Hyper-V
Microsoft's July 14 Patch Tuesday closed CVE-2026-57092 — a CVSS 9.9 use-after-free in the Windows VMSwitch that lets a low-privileged guest reach the Hyper-V host.
Microsoft's July 14 Patch Tuesday closed CVE-2026-57092 — a CVSS 9.9 use-after-free in the Windows VMSwitch that lets a low-privileged guest reach the Hyper-V host.
Microsoft's DART discovered CVE-2026-56155 during a live intrusion. CISA added it to KEV on July 14. Patch KB 5121391 audits DKM ACLs today, auto-remediates October 13.
Nightmare Eclipse published LegacyHive on GitHub the same day as Microsoft's July 2026 Patch Tuesday. It's an unpatched profsvc LPE that still works on fully-updated Windows.
CISA added SharePoint auth-bypass CVE-2026-56164 to KEV on July 14 and re-issued a hardening alert citing three chained on-prem SharePoint CVEs under active exploitation. FCEB deadline July 17.
Microsoft shipped Malware Protection Engine 1.1.26060.3008 on July 9 to close a race condition in mpengine.dll that hands SYSTEM to any local user. Public PoC has been circulating for a month.
CISA added SharePoint RCE CVE-2026-45659 to the KEV catalog on July 1 after confirmed exploitation. Deserialization bug patched OOB May 21; FCEB agencies have three days.
Microsoft's June 9 Patch Tuesday fixes around 200 CVEs and 33 Critical flaws, including publicly disclosed zero-days in BitLocker, HTTP.sys (HTTP/2 Bomb) and CTFMON.
Researcher Ammar Askar dropped a webview-postMessage exploit on June 2 that steals github.dev OAuth tokens via a single click. Microsoft shipped a stopgap fix the next day.
Belgium's CCB confirms active exploitation of the CVSS 9.8 Netlogon stack-overflow patched by Microsoft in May. Unauthenticated, no user interaction, domain controller takeover.