LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-21525: Microsoft Windows NULL Pointer Dereference Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 10, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 3, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-21525 to its Known Exploited Vulnerabilities catalog on Feb 10, 2026, with a federal patch deadline of Mar 3, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally.

This vulnerability is a null pointer dereference in the Remote Access Connection Manager component of Microsoft Windows. An unauthorized attacker with local access can trigger it to crash the service and deny availability. It matters for Windows environments that rely on this component for remote access functions, as the issue requires no network access and can be triggered locally.

How it works

The weakness is classified under CWE-476. In this class of flaw, program code attempts to read or write through a pointer variable whose value is null because initialization or error checking failed earlier in execution.

An attacker with local access supplies input or environmental conditions that cause the Remote Access Connection Manager to reach the defective code path, dereference the null pointer, and terminate the process.

Am I affected? How to find it in your systems

The affected component runs on Microsoft Windows systems where remote access features are present or enabled. Begin inventory by enumerating Windows endpoints and servers, then inspect running services for Remote Access Connection Manager.

How to remediate

Apply the vendor update named in the advisory as the primary step. After patching, review dependent services and configurations that interact with Remote Access Connection Manager.

If you can't patch immediately

Limit local execution opportunities through endpoint controls and user privilege restrictions. Monitor Windows Event Logs and service health metrics for sudden crashes that match the affected component.

If your data may have been exposed

Denial-of-service conditions from exploited vulnerabilities can form part of broader attack sequences that result in data exposure. You can run a free exposure scan of your email addresses to check against known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-476
Added to CISA KEVFeb 10, 2026
Federal patch deadlineMar 3, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities