ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz1

Microsoft Patch Tuesday: 6 exploited zero-days fixed in February 2026

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-21510
+4 in the same advisory: …21513 …21533 …21519 …21525
Security Feature Bypass in Microsoft Windows Shell Actively Exploited (CVE-2026-21510)

Microsoft Windows Shell contains a protection mechanism failure (CWE-693) that allows an unauthorized attacker to bypass a security feature, which CISA notes can be reached over a network. Successful exploitation defeats a Windows defense-in-depth control, weakening protections an attacker would otherwise have to evade as part of a broader intrusion; the available data does not describe a code-execution or privilege-escalation gain. Any system running Microsoft Windows falls within CISA's published affected scope, and specific version ranges have not been enumerated in the available data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-10, confirming exploitation in the wild, and its EPSS score of 26.2% (98th percentile) signals elevated near-term exploitation risk; ransomware use is unknown and no public proof-of-concept is known.

Do: Apply Microsoft's applicable Windows security update through Windows Update/WSUS or your patch-management process as soon as practical, prioritizing internet-exposed and high-value systems; because the issue is in CISA's KEV catalog (added 2026-02-10), U.S. federal agencies must apply the vendor fix, applicable BOD 22-01 mitigations (including for cloud services), or discontinue use by the catalog due date. Until patched, follow Microsoft's mitigation guidance from vendor advisories and monitor for updates, since specific affected builds and the exploited security feature have not been detailed in the available data.

8.8
group max
26% KEV
  • Microsoft Windows
mass≈1+ billion Windows devices
CVE-2026-21514
Actively Exploited Security Feature Bypass in Microsoft Word (CVE-2026-21514)

CVE-2026-21514 is a security feature bypass in Microsoft Word caused by the application relying on untrusted inputs when making a security decision (CWE-807). The flaw carries a local attack vector with a user-interaction requirement, so it is most plausibly triggered when a user opens attacker-supplied content, such as a crafted document, on a system running Word. A local, unauthorized attacker who exploits it can circumvent a Word security feature, with high-impact confidentiality, integrity, and availability effects on the local system; bypasses of this type are commonly chained with other flaws for deeper compromise. Any organization running Microsoft 365 Apps or Office Long Term Servicing Channel (LTSC) is affected. CISA added the bug to the Known Exploited Vulnerabilities catalog on 2026-02-10, confirming exploitation in the wild, though no public proof-of-concept is known and EPSS currently estimates a 1.5% chance of exploitation in the next 30 days (73rd percentile).

Do: Apply the February 2026 Patch Tuesday security updates from Microsoft for Microsoft 365 Apps and Office LTSC immediately; fixed version numbers were not provided in the source data, so use Microsoft's release guidance to confirm builds. Because the flaw is in CISA KEV, federal agencies must satisfy BOD 22-01 by applying the update (or directed mitigations) within the mandated weeks, and all organizations should prioritize endpoints that open untrusted documents. Until patched, consider Office hardening such as marking files from the internet as untrusted in Word and watching for anomalous document-driven local activity.

7.82% KEV
  • Microsoft 365 Apps
  • Microsoft Office Long Term Servicing Channel (LTSC)
  • Microsoft Office (broadly listed by CISA)
masshundreds of millions of users (Word is bundled in Microsoft 365 and Office across most enterprise desktop fleets)
Full article620 words · extracted from helpnetsecurity.com · click to collapse

Microsoft has plugged 50+ security holes on February 2026 Patch Tuesday, including six zero-day vulnerabilities exploited by attackers in the wild.

The “security feature bypass” zero-days

Among the zero-days fixed are three vulnerabilities that allow attackers to bypass a security feature.

CVE-2026-21513 affects the MSHTML/Trident browser engine for the Microsoft Windows version of Internet Explorer, and CVE-2026-21514 affects Microsoft Word.

The former can be exploited by attackers by convincing a user to open a malicious HTML or shortcut (.lnk) file that has been crafted to manipulate browser and Windows Shell handling.

The latter can be triggered by a malicious Office file crafted to bypass OLE mitigations in Microsoft 365 and Microsoft Office. (If this sounds familiar, it’s because Microsoft recently fixed a similar flaw with an emergency update due to in-the-wild attacks.)

CVE-2026-21510 is the third security feature bypass zero-day fixed this time around. It affects Windows Shell, can be exploited with a malicious link or shortcut file, allowing attackers to bypass Windows SmartScreen and Windows Shell security prompts and execute files “without user warning or consent.”

All three flaws were publicly known and reported by Google Threat Intelligence Group, Microsoft Threat Intelligence Center (MSTIC), Microsoft Security Response Center (MSRC), and the Office Product Group Security Team, along with an anonymous researcher.

Patching publicly known vulnerabilities should be a priority, especially if, like these, are actively exploited by attackers.

The three remaining zero-days

CVE-2026-21519 is a Desktop Window Manager vulnerability that allows attackers to elevate their privileges to SYSTEM on an already compromised host. It was reported by MSTIC and MSRC.

CVE-2026-21525 is a vulnerability in Windows Remote Access Connection Manager (“RasMan”) that may allow an unprivileged user to crash the service. It was reported by the 0patch research team, who discovered an exploit for it in a public malware repository.

CVE-2026-21533 is an elevation of privilege flaw affecting Windows Remote Desktop Services. It was reported by Crowdstrike researchers.

“The CVE-2026-21533 exploit binary modifies a service configuration key, replacing it with an attacker-controlled key, which could enable adversaries to escalate privileges to add a new user to the Administrator group. CrowdStrike Intelligence retrospective hunting has revealed that threat actors had used this binary in the wild to target U.S. and Canada-based entities since at least December 24, 2025,” the cybersecurity company noted.

“CrowdStrike Intelligence assesses that Microsoft’s public disclosure of CVE-2026-21533 will almost certainly encourage threat actors possessing CVE-2026-21533 exploit binaries, as well as any exploit brokers possessing the underlying exploit, to use or monetize the exploits in the near term.”

Ryan Braunstein, Security Manager at Automox, also pointed out that the RasMan DoS flaw (CVE-2026-21525) should be patched quickly, as it could lead to widespread problems, since the service is responsible for maintaining VPN connections to corporate networks.

“An attacker with a foothold as a standard, non-admin user can run a small script that crashes the RAS manager service. The attack requires no elevated privileges and can be triggered after initial access through phishing or a malicious browser extension,” he explained.

“Organizations relying on always-on VPN connections face a particular risk: if the VPN service crashes, endpoints configured with “fail close” policies lose network access entirely. IT teams can’t reach those machines to patch them or run automation. In larger environments, this creates cascading failures that can take hours to resolve.”

Such a widespread crash could be used a distraction while executing a separate attack against servers or exfiltrating data, he added. “If you run servers with RRAS (Routing and Remote Access Service), include them in your priority patching list to protect automations and infrastructure.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/02/11/february-2026-patch-tuesday/