Microsoft Patches CVE-2026-21525 Affecting Windows VPN Services

Microsoft Patches CVE-2026-21525 Affecting Windows VPN Services

First seen 12 Feb 2026, 21:16 UTC TechrepublicEsecurityplanetTheregister 30.8

Article Content

Browse articles
ThreatCluster

Microsoft has released a patch for CVE-2026-21525, a vulnerability in the RasMan component that can crash Windows VPN services and disrupt remote access. This flaw has been actively exploited, prompting its addition to the CISA KEV list on February 10, 2026.

Timeline

2026-02-10
CVE-2026-21525 published and added to CISA KEV
2026-02-11
Microsoft releases patch for CVE-2026-21525