
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21243 is a null pointer dereference vulnerability in Windows LDAP (Lightweight Directory Access Protocol) that allows an unauthenticated remote attacker to cause a denial of service over a network. It was disclosed and patched on February 10, 2026, as part of Microsoft's February 2026 Patch Tuesday security update release. Affected products include Windows Server 2019, Windows Server 2022, Windows Server 2022 23H2, and Windows Server 2025. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Microsoft MSRC).
The vulnerability is classified as CWE-476 (NULL Pointer Dereference), occurring within the Windows LDAP implementation. An attacker can send a specially crafted network request to a vulnerable Windows Server's LDAP service, triggering a null pointer dereference that causes the service to crash. Exploitation requires no authentication, no privileges, and no user interaction, and can be performed remotely over the network with low attack complexity (Microsoft MSRC).
Successful exploitation results in a denial of service condition, rendering LDAP-dependent directory services unavailable on affected Windows Server systems. Since LDAP is foundational to Active Directory operations, an outage could disrupt authentication, authorization, and directory lookups across an organization's environment. There is no impact to confidentiality or integrity; the sole impact is high availability loss (Microsoft MSRC).
Microsoft released patches on February 10, 2026, addressing this vulnerability across all affected Windows Server versions. Organizations should update to the following minimum build versions: Windows Server 2019 (10.0.17763.8389 or later), Windows Server 2022 (10.0.20348.4711 or later), Windows Server 2022 23H2 (10.0.25398.2149 or later), and Windows Server 2025 (10.0.26100.32313 or later) (Microsoft MSRC). As interim mitigations, administrators should implement network segmentation to restrict LDAP access (TCP/UDP port 389, LDAPS port 636) to authorized clients only, and monitor LDAP services for anomalous traffic or unexpected service crashes.
The vulnerability was covered as part of broader February 2026 Patch Tuesday roundups by security vendors and researchers. Rapid7, Qualys, BleepingComputer, and Sophos all included it in their Patch Tuesday review coverage, noting it as one of 58 vulnerabilities addressed that month alongside six actively exploited zero-days (Qualys Blog, BleepingComputer, Sophos Blog). General community sentiment treated this as a moderate-priority patch given the lack of public exploit code and no reported active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."