Esecurityplanet
Microsoft Patches CVE-2026-21525 Affecting Windows VPN Services
First seen 12 Feb 2026, 21:16 UTC
•

•30.8
Export
Article Content
Browse articles
Microsoft has released a patch for CVE-2026-21525, a vulnerability in the RasMan component that can crash Windows VPN services and disrupt remote access. This flaw has been actively exploited, prompting its addition to the CISA KEV list on February 10, 2026.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2026-02-10
CVE-2026-21525 published and added to CISA KEV
2026-02-11
Microsoft releases patch for CVE-2026-21525
More articles in this cluster
Continue Reading
Critical Vulnerabilities in Microsoft SCCM Enable Remote Code Execution for $58
CISA Issues Warning on SQL Injection Vulnerability in Microsoft Configuration Manager
CISA Adds New Vulnerabilities to Known Exploited Catalog
Multiple Vulnerabilities in Microsoft Products Identified
Windows 10 ESU Activation Requirements and Updates
Multiple Vulnerabilities Identified in Microsoft Products (CVE-2025)