
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21239 is a heap-based buffer overflow vulnerability in the Windows Kernel that allows a low-privileged local attacker to elevate privileges without user interaction. Disclosed on February 10, 2026, as part of Microsoft's February 2026 Patch Tuesday, it affects a wide range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), and Windows Server (2012, 2012 R2, 2016, 2019, 2022, 2025). It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).
The vulnerability is classified under CWE-122 (Heap-based Buffer Overflow) and CWE-787 (Out-of-bounds Write), with an associated attack pattern of CAPEC-92 (Forced Integer Overflow). An authorized local attacker with low privileges can trigger the overflow in the Windows Kernel, leading to out-of-bounds memory writes that can be leveraged for privilege escalation. No user interaction is required, and the attack complexity is low, making it straightforward to exploit once local access is obtained (Microsoft MSRC).
Successful exploitation grants the attacker SYSTEM-level privileges on the affected Windows system, resulting in high impact to confidentiality, integrity, and availability. An attacker could modify system files, install malware, access sensitive data, create new privileged accounts, or use the compromised system as a pivot point for lateral movement within a network. The broad scope of affected products — spanning consumer and server editions from Windows 10 1607 through Windows Server 2025 — significantly widens the potential attack surface (Microsoft MSRC).
Microsoft released patches on February 10, 2026, as part of the February 2026 Patch Tuesday update cycle. Administrators should apply the relevant cumulative updates for their Windows version: Windows 10 21H2 → 10.0.19044.6937 or later; Windows 10 22H2 → 10.0.19045.6937 or later; Windows 10 1809 → 10.0.17763.8389 or later; Windows 10 1607 → 10.0.14393.8868 or later; Windows 11 23H2 → 10.0.22631.6649 or later; Windows 11 24H2 → 10.0.26100.7781 or later; Windows 11 25H2 → 10.0.26200.7781 or later; Windows Server 2016 → 10.0.14393.8868 or later; Windows Server 2019 → 10.0.17763.8389 or later; Windows Server 2022 → 10.0.20348.4711 or later; Windows Server 2022 23H2 → 10.0.25398.2149 or later; Windows Server 2025 → 10.0.26100.32313 or later. As a complementary measure, organizations should enforce the principle of least privilege and restrict local interactive access to sensitive systems (Microsoft MSRC).
The vulnerability was covered as part of broader February 2026 Patch Tuesday roundups by security vendors including Qualys, Rapid7, Sophos, and BleepingComputer, which noted the overall release addressed 58 vulnerabilities including 6 zero-days. CVE-2026-21239 was not individually highlighted as a critical concern in these reviews, consistent with its lack of public exploit code or active exploitation (Qualys Blog, BleepingComputer, Sophos Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."