CVE-2026-21236Disclosure(microsoft / windows_10_1607)

MEDIUMCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

4.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-787

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 14 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 8 classified signals
  • General: 4 classified signals
  • Peaked 4d ago at 4 mentions (2026-03-18); latest day: 1
  • 14 total mentions across 9 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_server_2012windows_server_2016windows_server_2019

2 versions affected across 13 products

Deep dive

Activity timeline14 mentions / 9d
01234Mentions · 2026-02-10: 2Mentions · 2026-02-11: 1Mentions · 2026-03-03: 2Mentions · 2026-03-17: 1Mentions · 2026-03-18: 4Mentions · 2026-03-19: 1Mentions · 2026-03-27: 1Mentions · 2026-04-04: 1Mentions · 2026-06-22: 1PoC Mentioned / Linked · 2026-03-03: 1Exploit Tool / Code · 2026-06-22: 1Patch / Workaround · 2026-03-03: 1Technical Details · 2026-02-10: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-17: 1Technical Details · 2026-03-18: 2Technical Details · 2026-03-19: 102-1002-1103-0303-1703-1803-1903-2704-0406-22
Signal classification4 categories
Disclosure
857.1%
General
428.6%
PoC
17.1%
Exploit
17.1%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-02-102
Disclosure2
2026-02-111
Disclosure1
2026-03-032
General1PoC1
2026-03-171
Disclosure1
2026-03-184
Disclosure3General1
2026-03-191
Disclosure1
2026-03-271
General1
2026-04-041
General1
2026-06-221
Exploit1
Full discourse14 posts
  • Alex Plaskett@alexjplaskett
    Disclosure

    An analysis of CVE-2026-21236 - A heap based buffer overflow in the Microsoft Windows Kernel afd.sys - was just published by @ASN_Sinanju_06S a recent secondment with my team EDG! Nice work for her first triage of a kernel memory corruption bug! https://www.nccgroup.com/research/vulnerability-analysis-of-cve-2026-21236 https://t.co/Ca4tdcyioZ

    Post summary

    A new analysis of CVE-2026-21236, a heap‑based buffer overflow in Windows afd.sys, has been released, but the tweet does not disclose any PoC, exploit code, active exploitation, patch, or debunking claim.

    363122912816.0K
    13.5K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CVE-2026-21236: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability https://t.co/VNBwRI4S6R

    Post summary

    A tweet briefly announces CVE-2026-21236 as an elevation‑of‑privilege flaw in the Windows Ancillary Function Driver for WinSock, but offers no further details, PoC, exploit, or mitigation information.

    2191832612.2K
    174.6K followersView on X
  • PatchPoint.Official@_patchpoint_
    PoC

    We released a demo video for the CVE-2026-21236 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability, patched by Microsoft in Feb 2026. https://youtu.be/BUn9sIq8sm0 Watch the video and subscribe to our private vulnerability PoC and detailed report service at http://Patchpoint.io. #Windows #Microsoft #AFD #Vulnerability #CVE_2026_21236

    Post summary

    The post releases a demo video and PoC for CVE-2026-21236, confirms Microsoft has patched the vulnerability, and advertises a private vulnerability report service.

    013047255.5K
    463 followersView on X
  • NullSecurityX@NullSecurityX
    General

    CVE-2026-21236: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability #BugBounty #CyberSecurity https://t.co/FtQwe4gwiJ

    Post summary

    The tweet announces a newly identified Windows WinSock CVE, but offers no further technical details, PoC, or evidence of exploitation.

    08044183.3K
    11.8K followersView on X
  • ‘ALPAGU@alpagu995
    Disclosure

    CVE-2026-21236: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability https://t.co/qxBhDdPaKD

    Post summary

    A brief tweet announcing CVE‑2026‑21236 as an elevation‑of‑privilege vulnerability in the Windows Ancillary Function Driver for WinSock, with no further exploitation or patch details.

    00030169
    175 followersView on X
  • Alex Plaskett@alexjplaskett
    Exploit

    3/ Supporting secondees from other teams at NCC Auto-Pentester LLM Research - https://www.nccgroup.com/research/auto-pentester-llm-research/ Vulnerability Analysis of CVE-2026-21236 - https://www.nccgroup.com/research/vulnerability-analysis-of-cve-2026-21236/ VMWare guest to Host - https://www.nccgroup.com/research/vmware-workstation-guest-to-host-escape-exploit-development/

    Post summary

    The post provides links to research on CVE‑2026‑21236, including a vulnerability analysis and an exploit development article for a VMware guest‑to‑host escape.

    10010349
    13.8K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21236 Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. https://www.cve.org/CVERecord?id=CVE-2026-21236

    Post summary

    The post announces a heap-based buffer overflow in Windows Ancillary Function Driver for WinSock that permits local privilege escalation by authorized attackers.

    01010213
    56.5K followersView on X
  • VulnTracker@vuln_tracker
    General

    @alexjplaskett @ASN_Sinanju_06S This is how you build security research talent! CVE-2026-21236 kernel analysis by @ASN_Sinanju_0cs shows serious technical skill for a first kernel memory corruption triage. Windows afd.sys bugs are no joke - excellent mentorship! https://vulntracker.io/cves/CVE-2026-21236

    Post summary

    The tweet highlights a kernel memory corruption CVE (CVE-2026-21236) and recognizes a researcher's analysis, but provides no exploit, patch, or deployment details.

    00010201
    433 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-21513 2 - CVE-2025-14500 3 - CVE-2026-21236 4 - CVE-2026-2441 5 - CVE-2026-3223 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists five trending CVE identifiers without providing any additional context, technical details, or actionable information.

    00010166
    1.7K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Microsoft Windows (CVE-2026-21236) https://vuldb.com/?id.345262

    Post summary

    A new Microsoft Windows vulnerability (CVE-2026-21236) has been disclosed with increased severity, referenced through a VULDB link.

    0001075
    2.1K followersView on X
  • peteribí@peteribi
    General

    CVE-2026-21236. Kudos to Emily Liu and @NCCGroupInfosec. https://t.co/sxG05vhmBx

    Post summary

    The tweet merely acknowledges CVE‑2026‑21236 and thanks individuals, without providing technical or operational details.

    0000079
    79 followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    @DarkWebInformer AFD.sys heap buffer overflows never get old... CVE-2026-21236 hitting the WinSock driver is classic Windows kernel territory. Local privilege escalation through networking subsystem always makes defenders nervous. Tracking this one closely: http://vulntracker.io/cves/CVE-2026-21236

    Post summary

    The post announces CVE-2026-21236, a heap buffer overflow in Windows' WinSock driver that can lead to local privilege escalation, providing some technical details but no PoC, exploit, or patch information.

    0000075
    433 followersView on X
  • Milos Constantin ♏(@Tinolle hachyderm.io )@Tinolle
    Disclosure

    Vulnerability Analysis of CVE-2026-21236 https://www.nccgroup.com/research/vulnerability-analysis-of-cve-2026-21236/

    Post summary

    The text references an NCC Group analysis titled 'Vulnerability Analysis of CVE-2026-21236', but offers no further detail on exploitation or mitigation.

    0000037
    3.2K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-21236 - Microsoft - Windows 11 version 26H1 - https://www.redpacketsecurity.com/cve-alert-cve-2026-21236-microsoft-windows-11-version-26h1/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-21236 #microsoft #windows-11-version-26h1

    Post summary

    The tweet references a CVE alert for CVE-2026-21236 affecting Microsoft Windows 11 26H1 and provides a link to a security advisory, but offers no further technical or exploitation details.

    00000127
    3.5K followersView on X
CPE platform detail23 entries

23 of 23 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more