CVE-2026-21510
KEVmass1Security Feature Bypass in Microsoft Windows Shell Actively Exploited (CVE-2026-21510)
CISA: Microsoft Windows Shell Protection Mechanism Failure Vulnerability
Microsoft Windows Shell contains a protection mechanism failure (CWE-693) that allows an unauthorized attacker to bypass a security feature, which CISA notes can be reached over a network. Successful exploitation defeats a Windows defense-in-depth control, weakening protections an attacker would otherwise have to evade as part of a broader intrusion; the available data does not describe a code-execution or privilege-escalation gain. Any system running Microsoft Windows falls within CISA's published affected scope, and specific version ranges have not been enumerated in the available data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-10, confirming exploitation in the wild, and its EPSS score of 26.2% (98th percentile) signals elevated near-term exploitation risk; ransomware use is unknown and no public proof-of-concept is known.
What to do: Apply Microsoft's applicable Windows security update through Windows Update/WSUS or your patch-management process as soon as practical, prioritizing internet-exposed and high-value systems; because the issue is in CISA's KEV catalog (added 2026-02-10), U.S. federal agencies must apply the vendor fix, applicable BOD 22-01 mitigations (including for cloud services), or discontinue use by the catalog due date. Until patched, follow Microsoft's mitigation guidance from vendor advisories and monitor for updates, since specific affected builds and the exploited security feature have not been detailed in the available data.
| Microsoft Windows | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2022 23h2
- Weakness
- CWE-693
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H