CVE-2026-20876 | Microsoft Windows Virtualization-Based Security heap-based overflow
A vulnerability has been found in Microsoft Windows 11 23H2/11 24H2/11 25H2/Server 2022 23H2/Server 2025 and classified as critical. This vulnerability affects unknown code of the component Virtualization-Based Security. The manipulation leads to heap-based buffer overflow.
This vulnerability is referenced as CVE-2026-20876. The attack can only be performed from a local environment. No exploit is available.
Applying a patch is the recommended action to fix this issue.