Microsoft Patches Zero-Day Vulnerability in Windows RasMan Service

Microsoft Patches Zero-Day Vulnerability in Windows RasMan Service

First seen 11 Feb 2026, 16:28 UTC Api.Msrc.MicrosoftGbhackersCybersecuritynews 27.3

Article Content

Browse articles
ThreatCluster

Microsoft has addressed a zero-day vulnerability in the Windows Remote Access Connection Manager (RasMan) service, identified as CVE-2026-21525. This flaw, which allowed attackers to cause denial-of-service conditions on unpatched systems, was actively exploited prior to its disclosure. The vulnerability is linked to a NULL pointer dereference issue.

Timeline

2026-02-10
CVE-2026-21525 published
2026-02-10
CVE-2026-21525 added to CISA KEV (active exploitation)
2026-02-11
Microsoft announces patch for CVE-2026-21525