ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity1

February 2026 Patch Tuesday forecast: Lots of OOB love this month

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-8088
WinRAR Path Traversal (CVE-2025-8088) Enables Arbitrary Code Execution

A path traversal flaw (CWE-35) in the Windows version of WinRAR allows attackers to achieve arbitrary code execution by delivering a specially crafted archive file that writes outside the expected location when it is opened or processed. Because the CVSS 4.0 vector indicates a local attack requiring user interaction, victims are typically infected by extracting or previewing a malicious archive received via phishing, a malicious download, or another delivery channel. A successful attacker gains the privileges of the user running WinRAR, providing an initial foothold that has been used for both espionage and ransomware operations. Anyone running the Windows version of WinRAR — one of the most widely deployed Windows desktop utilities — is affected, and CPE data additionally lists dtSearch as an affected vendor. Exploitation is confirmed in the wild by nation-state actors (e.g., the China-linked Amaranth-Dragon group per related reporting) and criminal actors including ransomware operators; the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-12 and carries a near-maximal 94.6% EPSS score.

Do: Update WinRAR to the latest patched release from RARLAB on all Windows endpoints, prioritizing remediation per CISA KEV and BOD 22-01 requirements, and verify that dtSearch deployments bundling the affected component are also updated. Because exploitation requires a user to open or extract a crafted archive, warn users to treat unexpected archive files delivered by email or download with suspicion. Given confirmed ransomware use, hunt across user workstations — not just exposed servers — for suspicious archive-based infections and confirm the patched WinRAR version is installed.

8.495% KEV ransomware
  • RARLAB WinRAR
  • dtsearch
masshundreds of millions of Windows users/devices (est.; RARLAB has historically claimed user counts in the hundreds of millions)
CVE-2026-21509
Local Security Feature Bypass in Microsoft Office Under Active Exploitation

CVE-2026-21509 is a security feature bypass in Microsoft Office caused by reliance on untrusted input when making a security decision (CWE-807): Office trusts attacker-controlled data when deciding whether a protection applies, allowing an unauthorized local attacker to bypass that security feature. Exploitation is local and requires user interaction (per the CVSS vector), most plausibly by getting a user to open a crafted file or document, and the flaw carries high confidentiality, integrity, and availability impact. Anyone running Microsoft Office, Microsoft 365 Apps, or Office Long Term Servicing Channel is in scope, giving the flaw a potential audience in the hundreds of millions of seats. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-26, Microsoft issued an emergency patch, and headlines attribute in-the-wild use to Russian state hackers targeting Ukrainian and EU organizations, including the maritime and transport sectors (a related APT28 campaign was tied to a separate Office/MSHTML 0-day, CVE-2026-21513). EPSS estimates a 72.6% probability of exploitation within the next 30 days (99th percentile).

Do: Apply Microsoft's emergency Office update and the follow-on February 2026 Patch Tuesday fixes across Microsoft 365 Apps, Office, and Office LTSC, checking Microsoft's advisory for the exact affected builds since no version ranges are given in the source data. Given the KEV listing, federal agencies must patch per CISA BOD 22-01 timelines (or follow cloud-service guidance). Hunt for exploitation per vendor guidance — headlines report Russian state use against EU/Ukrainian and maritime/transport targets — and prioritize endpoints where users open untrusted files.

7.873% KEV
  • Microsoft Office
  • Microsoft 365 Apps
  • Microsoft Office Long Term Servicing Channel (LTSC)
masshundreds of millions of users/devices (Office and Microsoft 365 Apps have a global installed base on the order of 10^8+ seats)
Full article885 words · extracted from helpnetsecurity.com · click to collapse

Valentine’s Day is just around the corner and Microsoft has been giving us a lot of love with a non-stop supply of patches starting with January 2026 Patch Tuesday. The January releases addressed 92 vulnerabilities in Windows 11 and Server2025, as well as 79 vulnerabilities for Windows 10 and its associated servers. We also saw updates for legacy 2016 versions of Microsoft Office and even a SQL Server update. But these patches came with some problems because there were updates to address reported issues not long thereafter.

February 2026 Patch Tuesday forecast

Microsoft to roll up multiple OOB fixes for Windows and Office issues

The Microsoft releases coming up this Patch Tuesday will include three rounds of out-of-band (OOB) patches from January. The first set, released January 17th, addressed two issues introduced with the January 2026 Patch Tuesday updates. The first issue involved credential prompt failures when attempting remote desktop or remote appliance connections.

The second issue involved the failure of some devices to shut down or enter hibernation mode. The remote connection issue impacted all supported OS including Windows 10 and 11, as well as Windows Server 2019, 2022, and 2025. The shutdown and hibernation issue was limited to Windows 11, 23H2. The second OOB patch came on January 24th, one Saturday after the first set. This one literally hit ‘close to home’ for me as it blocked my personal mail. Again, an issue introduced in the January Patch Tuesday updates, Microsoft Outlook Classic would experience problems when reading or writing to the .pst mail file if the file uses cloud-based storage like OneDrive. These OOB patches applied to all the supported OS I have listed previously for the remote connection issue.

And finally, the third OOB patch on January 26th, addressed a security vulnerability in Microsoft Office. Microsoft addressed zero-day vulnerability CVE-2026-21509, a security bypass vulnerability, which impacts multiple versions of Office including Microsoft 365 Apps for Enterprise. The current exploit requires a user to open a malicious Office file, which then provides unauthorized access to the system. All of these OOB fixes will be included in the February preview as well as the security releases on Patch Tuesday.

Microsoft plans phased NTLM disablement

Microsoft released their plan for the phased disablement of New Technology LAN Manager (NTLM) in the latest operating systems starting now in 2026 and beyond. The NTLM authentication protocol was introduced back in 1993 and has since been superseded by Kerberos protocols, which are far more secure. However, NTLM has remained the fallback when Kerberos is unavailable despite being deprecated and having weak algorithms.

Phase one is all about identifying where NTLM may still be running and changing it out where you can. Starting now, Microsoft recommends using advanced NTLM auditing already available in Server 2025, and Windows 11 24H2 and newer. Phase two begins with major OS updates coming later this year. They will address the ‘pain points’ or blockers by removing where Kerberos reverts back to NTLM.

And finally in Phase three, which is determined by the next major Server update, NTLM will be disabled by default. The code will still be there, but you will need to explicitly re-enable it if absolutely needed. This three-phase approach will happen quickly, so plan appropriately to replace NTLM in your environment and take a giant security step forward.

Active exploits reported in WinRAR and Notepad++

Before moving on to the forecast, I’d like to point out the exploitation of two widely used applications reported in the news this month. The Google Threat Intelligence Group provided an extensive analysis of CVE-2025-8088, a path traversal vulnerability, which allows remote code execution in WinRAR. This popular archival program has become a favorite target of numerous threat actors to perform espionage and achieve financial gain.

The second program, NotePad++ reported a security exposure on their blog specifically “the attack involved infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org.” The latest security updates from both these vendors resolve these issues, but you may want to spend a little extra time reviewing your security posture to ensure there is no sign of compromise.

February 2026 Patch Tuesday forecast

  • We already know some of the performance and security updates we should see this month based on the OOB releases so far. Expect the usual OS and Microsoft Office updates (more 2016 legacy updates?) and perhaps a .NET framework update as well.
  • Adobe has been rotating the Creative Cloud Apps updates monthly. We may see updates for After Effects, Animate, Audition, Photoshop, and Premiere, if the trend continues.
  • Apple is overdue for a major set of OS and Safari updates, the last coming in December, so watch for those soon.
  • Several beta releases for Google Chrome 145 were released this week, so the GA versions should be coming Patch Tuesday.
  • Mozilla released Firefox 147.0.2, Thunderbird 147.0.1, and Thunderbird ESR 140.7.1 on January 27th. Since these are all minor releases, I anticipate the 148 version coming next week for their suite of apps.

February 2026 Patch Tuesday is the 10th this year, so let’s roll out the updates by the end of the week and plan a nice Valentine’s Day dinner for the weekend. Let’s just hope the patches are stable and we don’t get another OOB love fest from Microsoft anytime soon.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/02/06/february-2026-patch-tuesday-forecast/