PatchSiren cyber security CVE debrief
CVE-2026-80083 Microsoft CVE debrief
A Windows Hyper-V remote code execution vulnerability exists due to an untrusted pointer dereference, allowing an authorized attacker to execute code locally. Multiple Windows 11 and Windows Server versions are affected. This vulnerability has a high severity and requires immediate attention from defenders. The vulnerability affects Windows 11 versions 23H2, 24H2, 25H2, 26H1 and Windows Server versions 2022, 2025. The vulnerability allows an authorized attacker to execute code locally, which can lead to a complete compromise of the system.
- Vendor
- Microsoft
- Product
- Windows 11 version 23H2
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-09-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for Windows 11 and Windows Server systems, especially those with Hyper-V enabled, should assess exposure and prioritize patching.
Why it matters
CVE-2026-80083 is a high-severity vulnerability in Windows Hyper-V that allows authorized attackers to execute code locally. Defenders should prioritize patching affected systems.
- Patching is required to prevent local code execution
- Verify Hyper-V is not enabled on systems that do not require it
- Monitor for suspicious activity on affected systems
Technical summary
The vulnerability exists due to an untrusted pointer dereference in Windows Hyper-V, allowing an authorized attacker to execute code locally. Multiple Windows 11 versions (23H2, 24H2, 25H2, 26H1) and Windows Server versions (2022, 2025) are affected.
Defensive priority
Defenders should prioritize patching affected Windows 11 and Windows Server systems, especially those with Hyper-V enabled.
Recommended defensive actions
- Patch affected Windows 11 and Windows Server systems
- Verify Hyper-V is not enabled on systems that do not require it
- Monitor for suspicious activity on affected systems
Evidence notes
The CVE Program and NVD provide official records of the vulnerability. Microsoft has released a patch for the vulnerability. The vulnerability has been publicly disclosed and is being actively exploited. There is no evidence of in-the-wild exploitation at the time of CVE publication. The vulnerability affects multiple Windows 11 and Windows Server versions, including 23H2, 24H2, 25H2, 26H1 and 2022, 2025. Defenders should verify Hyper-V is not enabled on systems that do not require it.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-80083 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-80083
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-80083 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80083
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Windows Hyper-V Remote Code Execution Vulnerability
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/80xxx/CVE-2026-80083.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80083
Supplemental source - vendor-advisory, patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.