CVE-2026-21251
vulnerability analysis and mitigation

Overview

CVE-2026-21251 is a use-after-free vulnerability in the Windows Cluster Client Failover component that allows an authorized local attacker to elevate privileges. Disclosed on February 10, 2026, as part of Microsoft's Patch Tuesday release, it affects Windows Server 2016, 2019, 2022, 2022 23H2, 2025, and Server 23H2. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), meaning the Windows Cluster Client Failover component accesses memory after it has been freed, potentially allowing an attacker to control the freed memory region and redirect execution flow. Exploitation requires local access with low privileges and no user interaction, making it a straightforward local privilege escalation path. The attack vector is local (AV:L), with low attack complexity (AC:L) and low privileges required (PR:L), and the scope is unchanged (Microsoft MSRC, Feedly). No public technical write-ups or proof-of-concept code have been identified at this time.

Impact

Successful exploitation allows a low-privileged local attacker to escalate privileges to SYSTEM level, resulting in complete system compromise with high confidentiality, integrity, and availability impact. An attacker who gains SYSTEM-level access can execute arbitrary code, access all data on the system, disable security controls, and potentially use the compromised server as a pivot point for lateral movement within a Windows Server cluster environment (Microsoft MSRC, Feedly).

Mitigation and workarounds

Microsoft released security updates on February 10, 2026 to address this vulnerability. Administrators should update affected Windows Server versions to the following minimum builds: Windows Server 2025 to 10.0.26100.32313, Windows Server 2022 23H2 to 10.0.25398.2149, Windows Server 2022 to 10.0.20348.4711, Windows Server 2019 to 10.0.17763.8389, and Windows Server 2016 to 10.0.14393.8868 (Microsoft MSRC). As a defense-in-depth measure, restrict local access to cluster failover systems to only authorized administrative users and monitor for suspicious privilege escalation activity.

Community reactions

The vulnerability was covered as part of broader February 2026 Patch Tuesday roundups by security outlets including BleepingComputer, Rapid7, Sophos, and CyberSecurityNews, which collectively noted the patch addressed 58 vulnerabilities including 6 zero-days (BleepingComputer, Rapid7, Sophos). CVE-2026-21251 itself did not receive significant individual attention, as community focus was directed toward the actively exploited zero-days in the same release.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management