AI analysis
CVE-2026-78444 is an untrusted pointer dereference (CWE-822) in the Windows Failover Cluster (Failover Clustering) feature of Windows Server. Per the CVSS vector, it can be triggered by an unauthorized attacker over a network with no privileges or user interaction required, though the high attack complexity means reliable exploitation is more difficult than in typical unauthenticated RCE flaws. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability on the affected cluster node. Only environments running Windows Server with Failover Clustering enabled are affected. As of the September 2026 Security Update Review, there is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a 0.5% probability of exploitation within 30 days (42nd percentile).
What to do: Apply Microsoft's September 2026 security updates to every node in each failover cluster, since cluster patching is only complete when all nodes are updated. Check whether the Failover Clustering feature is enabled on any Windows Servers you manage and prioritize nodes reachable from untrusted network segments. Until patched, reduce exposure by restricting network access to cluster service endpoints through firewall and segmentation rules.
Affected
| Microsoft Windows Failover Cluster (Failover Clustering feature in Windows Server) | — |
Estimated exposure
large≈10,000–100,000 Windows Server cluster nodes (order-of-magnitude estimate; not directly measured) — Windows Server has a very large installed base and Failover Clustering is a standard high-availability feature in enterprise datacenters, so plausibly tens of thousands of cluster nodes exist worldwide, though exact counts are unpublished…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.