ZeroHour

CVE-2026-78444

large

Untrusted Pointer Dereference RCE in Windows Failover Cluster

CVSS 3.1
8.1 high
EPSS
<1%p42
Published
()
Modified
AI analysis

CVE-2026-78444 is an untrusted pointer dereference (CWE-822) in the Windows Failover Cluster (Failover Clustering) feature of Windows Server. Per the CVSS vector, it can be triggered by an unauthorized attacker over a network with no privileges or user interaction required, though the high attack complexity means reliable exploitation is more difficult than in typical unauthenticated RCE flaws. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability on the affected cluster node. Only environments running Windows Server with Failover Clustering enabled are affected. As of the September 2026 Security Update Review, there is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a 0.5% probability of exploitation within 30 days (42nd percentile).

What to do: Apply Microsoft's September 2026 security updates to every node in each failover cluster, since cluster patching is only complete when all nodes are updated. Check whether the Failover Clustering feature is enabled on any Windows Servers you manage and prioritize nodes reachable from untrusted network segments. Until patched, reduce exposure by restricting network access to cluster service endpoints through firewall and segmentation rules.

Affected
Microsoft Windows Failover Cluster (Failover Clustering feature in Windows Server)
Estimated exposure
large≈10,000–100,000 Windows Server cluster nodes (order-of-magnitude estimate; not directly measured) — Windows Server has a very large installed base and Failover Clustering is a standard high-availability feature in enterprise datacenters, so plausibly tens of thousands of cluster nodes exist worldwide, though exact counts are unpublished…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
windows 10 1809, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-822
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

The September 2026 Security Update Review

ZDI's September 2026 Microsoft update review lists two already-exploited Windows EoP zero-days and dozens of critical RCEs across Office, SQL Server, and Windows services.

The review catalogs Microsoft's September 2026 fixes, marking CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack) as already exploited elevation-of-privilege issues. It also lists critical RCE flaws in Office, Word, Excel, PowerPoint, Outlook, SQL Server, Windows DNS, DHCP and Failover Cluster, plus graphics component RCEs. Azure-side fixes include Entra ID, Copilot Studio, Azure AI Language and Azure AD B2C elevation-of-privilege flaws.