CVE-2026-21525Active Exploitation(microsoft / windows_10_1607)

HIGHCVSS 6.2 · MEDIUMCISA KEV

Exploitation observed; activity peaked at 13 mentions and remains active

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

6.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-03. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-476

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Active exploitation appears in 18 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 33 mentions across 10 observed days

What's happening

  • Active exploitation reported across 18 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 13 signals
  • Technical details provided in 22 signals
  • Disclosure: 7 classified signals
  • General: 6 classified signals
  • Peaked 8d ago at 13 mentions (2026-02-11); latest day: 1
  • 33 total mentions across 10 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_server_2012windows_server_2016windows_server_2019

2 versions affected across 13 products

Deep dive

Activity timeline33 mentions / 10d
0371013Mentions · 2026-02-10: 7Mentions · 2026-02-11: 13Mentions · 2026-02-12: 5Mentions · 2026-02-13: 1Mentions · 2026-02-18: 1Mentions · 2026-02-26: 1Mentions · 2026-02-27: 1Mentions · 2026-03-10: 1Mentions · 2026-05-08: 2Mentions · 2026-06-26: 1PoC Mentioned / Linked · 2026-06-26: 1Active Exploitation · 2026-02-10: 3Active Exploitation · 2026-02-11: 8Active Exploitation · 2026-02-12: 4Active Exploitation · 2026-02-27: 1Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-05-08: 1Patch / Workaround · 2026-02-10: 2Patch / Workaround · 2026-02-11: 6Patch / Workaround · 2026-02-12: 3Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-03-10: 1Technical Details · 2026-02-10: 4Technical Details · 2026-02-11: 10Technical Details · 2026-02-12: 3Technical Details · 2026-02-13: 1Technical Details · 2026-02-26: 1Technical Details · 2026-02-27: 1Technical Details · 2026-03-10: 1Technical Details · 2026-05-08: 102-1002-1102-1202-1302-1802-2602-2703-1005-0806-26
Signal classification5 categories
Active Exploitation
1442.4%
Disclosure
721.2%
General
618.2%
Patch
515.2%
PoC
13.0%
Referenced assets25 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-107
Active Exploitation2Disclosure3General1Patch1
2026-02-1113
Active Exploitation6Disclosure1General4Patch2
2026-02-125
Active Exploitation4Patch1
2026-02-131
Disclosure1
2026-02-181
General1
2026-02-261
Disclosure1
2026-02-271
Active Exploitation1
2026-03-101
Patch1
2026-05-082
Active Exploitation1Disclosure1
2026-06-261
PoC1
Full discourse20 posts
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CISA has added 6 vulnerabilities to the KEV Catalog CVE-2026-21513: Microsoft Internet Explorer Protection Mechanism Failure Vulnerability: Microsoft Internet Explorer contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. CVE-2026-21525: Microsoft Windows NULL Pointer Dereference Vulnerability: Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally. CVE-2026-21510: Microsoft Windows Shell Protection Mechanism Failure Vulnerability: Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. CVE-2026-21533: Microsoft Windows Improper Privilege Management Vulnerability: Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally. CVE-2026-21519: Microsoft Windows Type Confusion Vulnerability: Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally. CVE-2026-21514: Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability: Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally.

    Post summary

    CISA announces six new CVEs added to its KEV catalog, providing brief technical descriptions but no evidence of exploitation, PoCs, or available patches.

    09124104.8K
    164.8K followersView on X
  • BleepingComputer@BleepinComputer
    Active Exploitation

    Our Microsoft February 2026 Patch Tuesday article was updated to include some information on how CVE-2026-21533 and CVE-2026-21525 were found to be exploited.

    Post summary

    The updated Microsoft Patch Tuesday article indicates that CVE-2026-21533 and CVE-2026-21525 are being actively exploited.

    0301504.0K
    248.1K followersView on X
  • Horizon Secured@horizon_secured
    Active Exploitation

    🚨 𝗛𝗼𝗿𝗶𝘇𝗼𝗻 𝗔𝗹𝗲𝗿𝘁 – 𝗙𝗲𝗯𝗿𝘂𝗮𝗿𝘆 𝟮𝟬𝟮𝟲 𝗣𝗮𝘁𝗰𝗵 𝗧𝘂𝗲𝘀𝗱𝗮𝘆 February brings 𝟲 𝗮𝗰𝘁𝗶𝘃𝗲𝗹𝘆 𝗲𝘅𝗽𝗹𝗼𝗶𝘁𝗲𝗱 𝘇𝗲𝗿𝗼-𝗱𝗮𝘆𝘀, primarily focused on security feature bypass and privilege escalation. 𝗧𝗿𝗮𝗰𝗸𝗲𝗱 𝗖𝗩𝗘𝘀: 🔸 CVE-2026-21514 🔸 CVE-2026-21510 🔸 CVE-2026-21513 🔸 CVE-2026-21525 🔸 CVE-2026-21533 🔸 CVE-2026-21519 Multiple SYSTEM-level 𝗲𝗹𝗲𝘃𝗮𝘁𝗶𝗼𝗻-𝗼𝗳-𝗽𝗿𝗶𝘃𝗶𝗹𝗲𝗴𝗲 issues and 𝘂𝘀𝗲𝗿-𝗶𝗻𝘁𝗲𝗿𝗮𝗰𝘁𝗶𝗼𝗻 𝗱𝗼𝗰𝘂𝗺𝗲𝗻𝘁 𝗮𝘁𝘁𝗮𝗰𝗸𝘀 are already being exploited in the wild — making endpoint patch prioritization critical. 𝗙𝘂𝗹𝗹 𝗯𝗿𝗲𝗮𝗸𝗱𝗼𝘄𝗻 and insights available in this month’s 𝗛𝗼𝗿𝗶𝘇𝗼𝗻 𝗔𝗹𝗲𝗿𝘁: 🔗 https://horizon-secured.com/newsletter/ #HorizonAlert #Cybersecurity #PatchTuesday #ZeroDay

    Post summary

    The post alerts that six newly disclosed CVEs are being actively exploited in the wild, emphasizing the urgency of patching, but provides no technical exploit details or patch information.

    020931.1K
    2.2K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(2/10追加) 🛡️No.1509 CVE-2026-21510 Microsoft Windows Shell Protection Mechanism Failure Vulnerability ============= CVSSスコア: 8.8 (Base) / Microsoft Corporation CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:保護メカニズムの不具合 (CWE-693 / Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、悪意のあるリンクやショートカットファイルを介して、リモートよりWindows SmartScreen および Windows Shell のセキュリティプロンプトをバイパスされる恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21510 🛡️No.1510 CVE-2026-21513 Microsoft MSHTML Framework Security Feature Bypass Vulnerability ============= CVSSスコア: 8.8 (Base) / Microsoft Corporation CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:保護メカニズムの不具合 (CWE-693 / Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、細工されたHTMLファイルやショートかっとファイルを介して、リモートから、セキュリティ機能をバイパスされる恐れがあります。 https://msrc.microsoft.com/update-guide/advisory/CVE-2026-21513 🛡️No.1511 CVE-2026-21514 Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability ============= CVSSスコア: 7.8 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:セキュリティ決定の信頼できない入力への依存 (CWE-807/ Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 認証済みの攻撃者により、Officeファイルを介してローカル上でSYSTEM権限を取得される恐れがります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21514 🛡️No.1512 CVE-2026-21519 Microsoft Windows Type Confusion Vulnerability ============= CVSSスコア: 7.8 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 種別:型の取り違え (CWE-843/ Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 認証済みの攻撃者により、ローカル上でSYSTEM権限を取得される恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21519 🛡️No.1513 CVE-2026-21525 Microsoft Windows NULL Pointer Dereference Vulnerability ============= CVSSスコア: 6.2 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 種別:NULL ポインタデリファレンス (CWE-476 / Microsoft Corporation) 深刻度:注意 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、ローカル上でDoSを発生させられる恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21525 🛡️No.1514 CVE-2026-21533 Windows Remote Desktop Services Elevation of Privilege Vulnerability ============= CVSSスコア: 7.8 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 種別:不適切な権限管理 (CWE-269 / Microsoft Corporation) 深刻度:深刻🔥 ---------------------- 悪用時影響: 認証済みの攻撃者により、ローカル上でSYSTEM権限を取得される恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21533 CISA Adds Six Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/02/10/cisa-adds-six-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The post announces that CISA has added six CVEs with confirmed exploitation to its catalog, providing technical details and links to Microsoft advisories but no PoC, exploit code, or patch information.

    000834.7K
    42.5K followersView on X
  • Summercon@SummerC0n
    PoC

    🔒 Speaker spotlight: Asritha Bodepudi (@TrailofBits) is walking us through building a Windows N-day exploit chain — CVE-2025-59230 + CVE-2026-21525 — live at #Summercon2026, July 10–11 in Brooklyn. https://summercon2026.eventbrite.com

    Post summary

    The speaker plans to showcase a Proof of Concept exploit chain for CVE-2025-59230 and CVE-2026-21525 during Summercon2026, with no patches, active exploitation claims, or technical details disclosed.

    01030500
    3.8K followersView on X
  • Mitja Kolsek@mkolsek
    General

    @0patch The 0day thus became CVE-2026-21525 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21525

    Post summary

    The post announces CVE‑2026‑21525 and links to Microsoft’s update guide, but offers no further technical detail, PoC, or exploitation information.

    02010597
    4.0K followersView on X
  • CyberArts Siber Güvenlik ve Danışmanlık A.Ş.@cyberartspro
    Active Exploitation

    Microsoft’tan Kritik Şubat 2026 Güncellemesi! Sahada aktif sömürülen 6 adet Zero-Day açığı kapatıldı. Özellikle RasMan (CVE-2026-21525) zafiyeti, bağlantı kesintilerine ve operasyonel aksamalara yol açan DoS saldırılarına imkan tanıyor. 🛡️ Kurumlar, "aktif istismar" riski nedeniyle yama dağıtımını acilen önceliklendirmelidir. Analizimiz ve detaylar: 🔗https://www.cyberartspro.com/tr/microsoft-subat-2026-guvenlik-guncellemeleri/ #SiberGüvenlik #Microsoft #ZeroDay #CyberArts

    Post summary

    The text reports that six zero‑day vulnerabilities, including CVE‑2026‑21525, were actively exploited in the wild, causing DoS incidents, and urges immediate patch deployment.

    0101045
    143 followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISA、6つの既知の脆弱性をカタログに追加 CISA Adds Six Known Exploited Vulnerabilities to Catalog #CISA (Feb 10) CVE-2026-21510 Microsoft Windows シェル保護メカニズムの失敗の脆弱性 CVE-2026-21513 Microsoft MSHTML フレームワークのセキュリティ機能バイパスの脆弱性 CVE-2026-21514 Microsoft Office Word のセキュリティ決定における信頼できない入力への依存の脆弱性 CVE-2026-21519 Microsoft Windows の型混乱の脆弱性 CVE-2026-21525 Microsoft Windows の NULL ポインタ逆参照の脆弱性 CVE-2026-21533 Windows リモート デスクトップ サービスの権限昇格の脆弱性 https://www.cisa.gov/news-events/alerts/2026/02/10/cisa-adds-six-known-exploited-vulnerabilities-catalog

    Post summary

    CISA has added six Microsoft CVEs to its catalog, highlighting that they are actively exploited in the wild.

    00011354
    4.7K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Microsoft Patches Actively Exploited Windows RasMan Bug Crashing VPN Connections (CVE-2026-21525) Microsoft fixed an actively exploited NULL-pointer dereference in the Windows Remote Access Connection Manager (RasMan) that can be triggered locally to repeatedly crash the VPN/remote-access service and disrupt connectivity. This matters because it’s an availability-focused exploit against a core remote-work dependency, so unpatched endpoints can be forced offline until manual recovery. 🎯 Target: Global / Windows VPN & Remote Access #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.techrepublic.com/article/news-microsoft-rasman-cve-vpn/

    Post summary

    Microsoft released a patch for the actively exploited NULL‑pointer dereference in RasMan that caused VPN crashes, confirming the CVE’s real‑world impact.

    1001056
    191 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-21525: Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally.

    Post summary

    The post announces CVE-2026-21525, noting a NULL pointer dereference in Microsoft's Remote Access Connection Manager that could locally cause denial of service.

    1000042
    183 followersView on X
  • İmam Gazali@boo8ow1923
    Patch

    İşte güncel ve yamasız kritik güvenlik zafiyetlerinin CVE listesi, önem derecesine göre sıralanmış şekilde: ## Kritik Zafiyetler (CVSS 10.0 - En Yüksek Risk) - **Cisco Secure Firewall ürünleri**: Mart 2026 güncellemesinde 48 güvenlik açığı giderildi, bunlardan 2 tanesi CVSS 10.0 seviyesinde kritik açıklardır. Bu açıklar saldırganlara sistem kontrolü vermektedir.^4^ ## Sıfır Gün Açıkları (Aktif İstismar Riski) - **CVE-2026-21385**: Android için - sınırlı ve hedefli istismar edildiğine dair işaretler bulunan sıfır gün açığı^1^ - **CVE-2026-21510**: Windows Shell güvenlik özelliği atlama açığı^3^ - **CVE-2026-21513**: MSHTML Framework güvenlik özelliği atlama açığı^3^ - **CVE-2026-21514**: Microsoft Word güvenlik özelliği atlama açığı^3^ - **CVE-2026-21519**: Desktop Window Manager yetki yükseltme açığı^3^ - **CVE-2026-21533**: Remote Desktop Services yetki yükseltme açığı^3^ - **CVE-2026-21525**: Remote Access Connection Manager hizmet aksatma açığı^3^ ## Google Chrome Kritik Açıkları - **CVE-2026-3536**: ANGLE'da tamsayı taşması (Kritik)^10^ - **CVE-2026-3537**: PowerVR'da nesne yaşam döngüsü sorunu (Kritik)^10^ - **CVE-2026-3538**: Skia'da tamsayı taşması (Kritik)^10^ ## Yüksek Önemli Açıklar - **CVE-2026-3539**: DevTools'da nesne yaşam döngüsü sorunu (Yüksek)^10^ - **CVE-2026-3540**: WebAudio'da uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3541**: CSS'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3542**: WebAssembly'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3543**: V8'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3544**: WebCodecs'da heap buffer overflow (Yüksek)^10^ - **CVE-2026-3545**: Navigasyonda yetersiz veri doğrulama (Yüksek)^10^ ## Güncelleme Önerileri - **Windows 11**: KB5077181 (25H2/24H2) ve KB5075941 (23H2) güncellemeleri ile 6 sıfır gün açığı kapatıldı^3^ - **Android**: 2026-03-05 güvenlik yama seviyesi veya üzeri tüm açıkları giderir^1,2^ - **Google Chrome**: En son sürüme güncelleme yapılması kritik açıklar için zorunludur^1^ - **Cisco ürünleri**: Mart 2026 paket güvenlik güncellemesinin uygulanması gerekir^4^ Bu zafiyetler arasında özellikle sıfır gün açıkları ve CVSS 10.0 seviyesindeki açıklar en yüksek riski taşımaktadır ve acil olarak yamanması gerekmektedir.

    Post summary

    The text enumerates several critical CVEs, details their technical nature, and gives concrete patch/workaround recommendations, suggesting the primary focus is on mitigation rather than exploitation or false reports.

    0100071
    48 followersView on X
  • برهان الجابري@brhan_alja99287
    Disclosure

    الانهيار المفاجئ (CVE-2026-21525) 📉 هذه الثغرة تستهدف "مدير الاتصالات". يمكن للمهاجم استغلالها للتسبب في "شاشة الموت الزرقاء" (BSoD) وتعطيل جهازك أو خوادم الشركات عن العمل تماماً. #BSoD 8/8: كيف تحمي نفسك الآن؟ ✅

    Post summary

    CVE‑2026‑21525 is disclosed as a vulnerability that targets the Communication Manager, can cause a Blue Screen of Death (BSoD), and may disrupt user devices or corporate servers.

    1000048
    761 followersView on X
  • kawn@kawn2020
    Active Exploitation

    「CVE-2026-21510、CVE-2026-21513、CVE-2026-21514、CVE-2026-21519、CVE-2026-21525、CVE-2026-21533 の脆弱性について、Microsoft 社では悪用の事実を確認済みと公表しており、今後被害が拡大するおそれがあるため、至急、セキュリティ更新プログラムを適用してくだ…」 https://x.com/kawn2020/status/2021830907704095189

    Post summary

    Microsoft confirms active exploitation of CVE‑2026‑21510, ‑21513, ‑21514, ‑21519, ‑21525, and ‑21533 and urges immediate patching to prevent further damage.

    10000152
    89 followersView on X
  • kawn@kawn2020
    General

    #windowsupdate #microsoft (つづき) ・CVE-2026-21525 Windows リモート アクセス接続マネージャーのサービス拒否の脆弱性 ・CVE-2026-21533 Windows リモート デスクトップ サービスの特権昇格の脆弱性

    Post summary

    The tweet lists two new Windows CVEs (CVE‑2026‑21525 and CVE‑2026‑21533) with brief descriptions of the affected components, but it offers no further details on exploitation, patches, or ongoing attacks.

    10000130
    89 followersView on X
  • kawn@kawn2020
    Disclosure

    #windowsupdate #microsoft (つづき) ・CVE-2026-21525 6.2 Windows Remote Access Connection Manager ・CVE-2026-21533 7.8 Windows リモート デスクトップ -悪用される可能性が高い:5 件 ・CVE-2026-21231 7.8 Windows カーネル (つづく…)

    Post summary

    The tweet announces several Windows CVEs with severity scores and notes that five are likely to be exploited, but it provides no PoC, exploit code, or patch information.

    10000126
    89 followersView on X
  • Grok@grok
    Active Exploitation

    Here's a summary of the six actively exploited zero-days patched by Microsoft: - CVE-2026-21510 (CVSS 8.8): Windows Shell protection failure; allows network-based security bypass. - CVE-2026-21513 (CVSS 8.8): MSHTML flaw; bypasses prompts for malicious files via HTML. - CVE-2026-21514 (CVSS 7.8): Office Word untrusted inputs; local security bypass via Office files. - CVE-2026-21519 (CVSS 7.8): Desktop Window Manager type confusion; local privilege escalation to SYSTEM. - CVE-2026-21525 (CVSS 6.2): Remote Access Connection Manager null pointer; local DoS. - CVE-2026-21533 (CVSS 7.8): Remote Desktop privilege mismanagement; local escalation to SYSTEM. Update ASAP!

    Post summary

    Microsoft has patched six zero‑day vulnerabilities that were actively exploited, each described with CVSS scores and a short technical overview.

    00010466
    8.1M followersView on X
  • Grok@grok
    Active Exploitation

    Here are key security bug fixes in the Feb 2026 Windows 11 update (KB5075941): - CVE-2026-21510: Windows Shell bypasses SmartScreen via malicious links (exploited). - CVE-2026-21513: MSHTML bypasses network security (exploited). - CVE-2026-21514: Word bypasses OLE mitigations (exploited). - CVE-2026-21519: Desktop Window Manager privilege escalation (exploited). - CVE-2026-21525: Remote Access DoS via null pointer (exploited). - CVE-2026-21533: Remote Desktop privilege elevation (exploited). Also fixes Secure Boot certs, VSM shutdown issues, Defender logging, and GPU security checks. Total: 58 flaws patched. For full list, check Microsoft's update guide.

    Post summary

    The February 2026 Windows 11 update (KB5075941) patched several CVEs that were actively exploited, including Shell, MSHTML, Word, Desktop Window Manager, Remote Access, and Remote Desktop vulnerabilities, along with other security fixes.

    10000311
    8.1M followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21525 Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally. https://www.cve.org/CVERecord?id=CVE-2026-21525

    Post summary

    The text announces CVE‑2026‑21525, a local denial‑of‑service vulnerability due to a null pointer dereference in Windows Remote Access Connection Manager.

    00010155
    56.5K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://lyrie.ai/research/research/active-exploit-cve-2026-21525-windows #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The snippet indicates that CVE‑2026‑21525 on Windows is actively exploited, but concrete details or mitigations are not disclosed.

    0000027
    183 followersView on X
  • Vicarius@vicariusltd
    Active Exploitation

    That's gotta hurt 😵 ____ CVE of the Week CVE-2026-21525: Critical Denial of Service in Windows RasMan This flaw allows unauthorized local attackers to trigger a null pointer dereference, causing the service to crash and immediately terminating active VPN and dial-up connections. This flaw is currently being exploited in the wild, leading to its inclusion in CISA's Known Exploited Vulnerabilities catalog. Exploiting it could result in: - Service Unavailability: Continuous crashing of the RasMan service prevents new connections from being established. - System Instability: Local attackers can weaponize this to disrupt critical infrastructure without needing elevated privileges. Recommended actions: 1. Apply February 2026 Updates: Install the latest cumulative security updates to patch the rasman.dll component. 2. Harden Access: Ensure the principle of least privilege is enforced to limit local access on sensitive gateway systems. If you cannot patch, use the scripts below to disable the RasMan service and reduce exposure. Detection: https://www.vicarius.io/vsociety/posts/cve-2026-21525-detection-script-dos-vulnerability-in-windows-remote-access-connection-manager Remediation: https://www.vicarius.io/vsociety/posts/cve-2026-21525-mitigation-script-dos-vulnerability-in-windows-remote-access-connection-manager Let us know if you need any help! Happy mitigating!

    Post summary

    CVE-2026-21525 is a critical local denial‑of‑service flaw in Windows RasMan that is actively exploited in the wild, as noted by its inclusion in the CISA KEV catalog, with vendor patches and mitigation scripts available.

    00000125
    2.2K followersView on X
CPE platform detail23 entries

23 of 23 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more