CVE-2026-21525
KEVmass1Local Denial-of-Service Flaw in Microsoft Windows Remote Access Connection Manager
CISA: Microsoft Windows NULL Pointer Dereference Vulnerability
CVE-2026-21525 is a null pointer dereference (CWE-476) in the Windows Remote Access Connection Manager (RasMan) component that can be triggered by an unauthorized attacker with local access to an affected machine, without valid credentials or user interaction. Triggering the flaw crashes the service or system, yielding a high-availability-impact denial of service with no confidentiality or integrity loss. Any organization running the affected Windows 10, Windows 11, or Windows Server builds is in scope, because the vulnerable component ships as part of the operating system. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-10, confirming active in-the-wild exploitation, and it was among the 59 fixes (including six actively exploited zero-days) in Microsoft's February 2026 Patch Tuesday. EPSS estimates a 5.0% probability of exploitation within 30 days (92nd percentile); no public proof-of-concept code is known.
What to do: Deploy the February 2026 Patch Tuesday Windows security updates to all affected Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), and Windows Server 2012/2016/2019/2022/2022 23H2 systems; organizations bound by CISA BOD 22-01 must remediate within the required timeline or apply vendor mitigations. Because the attack vector is local and no public PoC or documented workaround exists, patching is the primary mitigation — prioritize multi-user servers, remote-access/VDI hosts, and shared endpoints, and confirm deployment through your patch-management reporting.
| microsoft Windows 10 | 1607 |
| microsoft Windows 10 | 1809 |
| microsoft Windows 10 | 21H2 |
| microsoft Windows 10 | 22H2 |
| microsoft Windows 11 | 23H2 |
| microsoft Windows 11 | 24H2 |
| microsoft Windows 11 | 25H2 |
| microsoft Windows Server 2012 | 2012 |
| microsoft Windows Server 2016 | 2016 |
| microsoft Windows Server 2019 | 2019 |
| microsoft Windows Server 2022 | 2022 |
| microsoft Windows Server 2022 | 2022 23H2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2022 23h2
- Weakness
- CWE-476
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H