LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-21519: Microsoft Windows Type Confusion Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 10, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 3, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-21519 to its Known Exploited Vulnerabilities catalog on Feb 10, 2026, with a federal patch deadline of Mar 3, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.

Microsoft Desktop Windows Manager in Microsoft Windows contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges on an affected system. The issue is tracked as CVE-2026-21519 and is classified under CWE-843. Local privilege elevation flaws of this kind matter because they can expand the reach of an attacker who already has a foothold on a Windows host.

How it works

CWE-843 describes a type confusion condition in which code treats an object or data structure as a different type than intended. In the Desktop Windows Manager component, this mismatch can be reached by an authorized local user. The resulting inconsistency may let the attacker perform operations that would otherwise be blocked by privilege boundaries.

Exploitation requires local access and does not rely on remote code execution. No further mechanics are documented in the available summary.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that include the Desktop Windows Manager component. Inventory all Windows endpoints and servers, paying particular attention to those running user-interactive sessions where the window manager is active. Confirm whether any listed versions or configurations match the details in the vendor advisory.

How to remediate

Apply the update or mitigation instructions published by Microsoft for CVE-2026-21519. The primary action is to install the vendor-supplied fix once it is available for the affected Windows versions.

If you can't patch immediately

Until the vendor update can be deployed, apply mitigations exactly as described in the Microsoft advisory. If those mitigations are unavailable, discontinue use of the affected product. For cloud services, adhere to applicable BOD 22-01 requirements. Monitor local authentication and process-creation events for signs of privilege-escalation attempts while the exposure remains.

If your data may have been exposed

Actively exploited vulnerabilities can lead to breaches. You can run a free exposure scan of your email addresses to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-843
Added to CISA KEVFeb 10, 2026
Federal patch deadlineMar 3, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities