CVE-2026-21519

HIGH(7.8)KEV

Microsoft Windows Type Confusion Vulnerability

Description

Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

KEV Information

Vendor
Microsoft
Product
Windows
Date Added
February 10, 2026
Due Date
March 3, 2026
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
microsoftwindows 10 1607< 10.0.14393.8868
microsoftwindows 10 1809< 10.0.17763.8389
microsoftwindows 10 21h2< 10.0.19044.6937
microsoftwindows 10 22h2< 10.0.19045.6937
microsoftwindows 11 23h2< 10.0.22631.6649
microsoftwindows 11 24h2< 10.0.26100.7781
microsoftwindows 11 25h2< 10.0.26200.7781
microsoftwindows server 2016< 10.0.14393.8868
microsoftwindows server 2019< 10.0.17763.8389
microsoftwindows server 2022< 10.0.20348.4711
microsoftwindows server 2022 23h2< 10.0.25398.2149
microsoftwindows server 2025< 10.0.26100.32313

References

CVSS Score

7.8
HIGH(7.8)

EPSS Score

EPSS Score2.42%
EPSS Percentile82.4%

Dates

PublishedFebruary 10, 2026
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.