Junglewise Threat Intelligence

CVE-2026-72989: Microsoft Windows Failover Cluster information disclosure via uninitialized resource

CVE-2026-72989 · Severity: high · CVSS 7.5 · Published 2026-09-08

Executive brief

Windows Failover Cluster is a Microsoft system component used to provide high availability for critical business services and applications. A flaw in how the system initializes resources allows an unauthenticated attacker on the network to read sensitive information from cluster memory, potentially exposing configuration details, credentials, or other protected data.

Technical details

A use-of-uninitialized-resource vulnerability exists in Windows Failover Cluster where memory buffers are not properly initialized before being transmitted or exposed over the network. The vulnerability is network-reachable and does not require authentication or user interaction. An attacker can send crafted network requests to trigger the uninitialized memory disclosure, leaking sensitive information that may include cluster configuration, authentication tokens, or other protected data. Microsoft has released patches to address this issue.

Affected products

  • Microsoft Windows Failover Cluster

Timeline

  • 2026-09-08: disclosed

References

Related threats