CVE-2026-21525

Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

  • Published Feb 10, 2026
  • CVSS 6.2 medium
  • 4.8% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog

Affected software

CVE-2026-21525 at the National Vulnerability Database