ThreatCluster

Microsoft Addresses NPD Issues in VXLAN with CVEs-2025-39850 and CVE-2025-39851

First seen 18 Feb 2026, 09:15 UTC Api.Msrc.Microsoft 41

Article Content

Browse articles
ThreatCluster

Microsoft has published information regarding two vulnerabilities in the VXLAN protocol, identified as CVE-2025-39850 and CVE-2025-39851. Both vulnerabilities, published on September 19, 2025, involve null pointer dereference (NPD) issues when using nexthop objects in specific functions. Affected systems may experience instability or crashes due to these vulnerabilities.

Timeline

2025-09-19
CVE-2025-39850 published
2025-09-19
CVE-2025-39851 published
2026-02-18
Information published regarding CVEs-2025-39850 and 39851