Junglewise Threat Intelligence

CVE-2026-78444: Microsoft Windows Failover Cluster untrusted pointer dereference

CVE-2026-78444 · Severity: high · CVSS 8.1 · Published 2026-09-08

Executive brief

Windows Failover Cluster, a critical system component that manages high-availability services across networked servers, contains a vulnerability allowing remote code execution. An attacker can exploit this over the network without authentication, potentially gaining complete control over cluster infrastructure and the applications it manages.

Technical details

The vulnerability is a untrusted pointer dereference in Windows Failover Cluster that permits remote code execution. An unauthenticated attacker can trigger this flaw over the network without requiring user interaction or elevated privileges. Successful exploitation allows arbitrary code execution with cluster-level privileges, potentially compromising all systems managed by the failover cluster. A patch is available from Microsoft.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats