
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21251 is a use-after-free vulnerability in the Windows Cluster Client Failover component that allows an authorized local attacker to elevate privileges. Disclosed on February 10, 2026, as part of Microsoft's Patch Tuesday release, it affects Windows Server 2016, 2019, 2022, 2022 23H2, 2025, and Server 23H2. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).
The vulnerability is classified as CWE-416 (Use After Free), meaning the Windows Cluster Client Failover component accesses memory after it has been freed, potentially allowing an attacker to control the freed memory region and redirect execution flow. Exploitation requires local access with low privileges and no user interaction, making it a straightforward local privilege escalation path. The attack vector is local (AV:L), with low attack complexity (AC:L) and low privileges required (PR:L), and the scope is unchanged (Microsoft MSRC, Feedly). No public technical write-ups or proof-of-concept code have been identified at this time.
Successful exploitation allows a low-privileged local attacker to escalate privileges to SYSTEM level, resulting in complete system compromise with high confidentiality, integrity, and availability impact. An attacker who gains SYSTEM-level access can execute arbitrary code, access all data on the system, disable security controls, and potentially use the compromised server as a pivot point for lateral movement within a Windows Server cluster environment (Microsoft MSRC, Feedly).
Microsoft released security updates on February 10, 2026 to address this vulnerability. Administrators should update affected Windows Server versions to the following minimum builds: Windows Server 2025 to 10.0.26100.32313, Windows Server 2022 23H2 to 10.0.25398.2149, Windows Server 2022 to 10.0.20348.4711, Windows Server 2019 to 10.0.17763.8389, and Windows Server 2016 to 10.0.14393.8868 (Microsoft MSRC). As a defense-in-depth measure, restrict local access to cluster failover systems to only authorized administrative users and monitor for suspicious privilege escalation activity.
The vulnerability was covered as part of broader February 2026 Patch Tuesday roundups by security outlets including BleepingComputer, Rapid7, Sophos, and CyberSecurityNews, which collectively noted the patch addressed 58 vulnerabilities including 6 zero-days (BleepingComputer, Rapid7, Sophos). CVE-2026-21251 itself did not receive significant individual attention, as community focus was directed toward the actively exploited zero-days in the same release.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."