KEV · Actively exploited
CVE-2026-21525
MEDIUM 6.2
KEV
Windows Remote Access Connection Manager Denial of Service Vulnerability
EPSS
9.39%
above median
percentile 92.9%
CISA Known Exploited Vulnerability
- Added to KEV
- 2026-02-10
- Remediation deadline
- 2026-03-03
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Ransomware
- No
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
- Windows Fixed in Windows Server 2025 (Server Core installation) 10.0.26100.32370 Windows Server 2025 10.0.26100.32370 Windows Server 2022 (Server Core installation) 10.0.20348.4773 Windows Server 2022 10.0.25398.2149 Windows Server 2019 (Server Core installation) 10.0.17763.8389 Windows Server 2019 10.0.17763.8389 Windows Server 2016 (Server Core installation) 10.0.14393.8868 Windows Server 2016 10.0.14393.8868 Windows 11 26H1 · 2026-H1 10.0.28000.1575 Windows 11 25H2 · 2025-H2 10.0.26200.7840 Windows 11 24H2 · 2024-H2 10.0.26100.7840 Windows 11 23H2 · 2023-H2 10.0.22631.6649 Windows 10 22H2 · 2022-H2 10.0.19045.6937 Windows 10 21H2 · 2021-H2 10.0.19044.6937 Windows 10 1809 · 2018-09 10.0.17763.8389 Windows 10 1607 · 2016-07 10.0.14393.8868