CVE-2026-21222
vulnerability analysis and mitigation

Overview

CVE-2026-21222 is an information disclosure vulnerability in the Windows Kernel caused by the insertion of sensitive information into log files (CWE-532). An authorized local attacker with low privileges can exploit this flaw to disclose sensitive information stored in kernel log files. The vulnerability was disclosed and patched on February 10, 2026, as part of Microsoft's Patch Tuesday security update cycle. Affected products span a wide range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2), Windows Server 2012 R2, 2016, 2019, 2022, 2022 23H2, and 2025. It carries a CVSS v3.1 base score of 5.5 (Medium) (Microsoft MSRC).

Technical details

The root cause is classified as CWE-532 (Insertion of Sensitive Information into Log File), where the Windows Kernel writes sensitive data — potentially including credentials or confidential system information — into log files that are accessible to low-privileged local users. The attack vector is local, requiring an authenticated user account with low privileges and no user interaction or elevated permissions. No public technical write-ups or proof-of-concept code have been identified at this time (Microsoft MSRC).

Impact

Successful exploitation allows an authorized local attacker with low privileges to read sensitive information written to Windows Kernel log files, with a high confidentiality impact and no integrity or availability impact. Exposed data may include credentials or other confidential system information, which could facilitate privilege escalation or lateral movement if harvested credentials are reused. The vulnerability affects a broad set of Windows client and server platforms, increasing the potential attack surface across enterprise environments (Microsoft MSRC).

Mitigation and workarounds

Microsoft released patches on February 10, 2026, addressing this vulnerability across all affected Windows versions. Patched build versions include: Windows 11 23H2 (10.0.22631.6649), Windows 11 24H2 (10.0.26100.7781), Windows 10 21H2 (10.0.19044.6937), Windows 10 22H2 (10.0.19045.6937), Windows Server 2016 (10.0.14393.8868), Windows Server 2019 (10.0.17763.8389), Windows Server 2022 (10.0.20348.4711), Windows Server 2022 23H2 (10.0.25398.2149), and Windows Server 2025 (10.0.26100.32313). As interim measures, organizations should restrict local access to affected systems to authorized users only, implement access controls limiting who can read kernel log files, and monitor log file access for unauthorized activity (Microsoft MSRC).

Community reactions

The vulnerability was covered as part of broader February 2026 Patch Tuesday roundups by multiple security outlets. Qualys, Rapid7, Sophos, and BleepingComputer all included it in their Patch Tuesday review coverage, though it received minimal individual attention given its medium severity and local-only attack vector. The broader February 2026 Patch Tuesday was notable for fixing 6 zero-day vulnerabilities and 58 total flaws, which drew more community focus than this specific CVE (Qualys Blog, BleepingComputer, Sophos Blog).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management