CVE-2026-21525
Microsoft · Published February 10, 2026
6.2
CVSS v3.1
MEDIUMCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.
Affected Products
- Windows 10 1607 < 10.0.14393.8868
- Windows 10 1809 < 10.0.17763.8389
- Windows 10 21h2 < 10.0.19044.6937
- Windows 10 22h2 < 10.0.19045.6937
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H