CVE-2026-21250 | Microsoft Windows HTTP.sys untrusted pointer dereference
A vulnerability was found in Microsoft Windows 11 24H2/11 25H2/11 26H1/Server 2022 23H2/Server 2025. It has been rated as critical. The impacted element is an unknown function in the library HTTP.sys. The manipulation leads to untrusted pointer dereference.
This vulnerability is referenced as CVE-2026-21250. The attack can only be performed from a local environment. No exploit is available.
To fix this issue, it is recommended to deploy a patch.