ZeroHour
CyberScooppublished ()ingested @CyberScoopNews1

Microsoft Patch Tuesday matches last year’s zero-day high with six actively exploited vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-21510
+4 in the same advisory: …21513 …21533 …21519 …21525
Security Feature Bypass in Microsoft Windows Shell Actively Exploited (CVE-2026-21510)

Microsoft Windows Shell contains a protection mechanism failure (CWE-693) that allows an unauthorized attacker to bypass a security feature, which CISA notes can be reached over a network. Successful exploitation defeats a Windows defense-in-depth control, weakening protections an attacker would otherwise have to evade as part of a broader intrusion; the available data does not describe a code-execution or privilege-escalation gain. Any system running Microsoft Windows falls within CISA's published affected scope, and specific version ranges have not been enumerated in the available data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-10, confirming exploitation in the wild, and its EPSS score of 26.2% (98th percentile) signals elevated near-term exploitation risk; ransomware use is unknown and no public proof-of-concept is known.

Do: Apply Microsoft's applicable Windows security update through Windows Update/WSUS or your patch-management process as soon as practical, prioritizing internet-exposed and high-value systems; because the issue is in CISA's KEV catalog (added 2026-02-10), U.S. federal agencies must apply the vendor fix, applicable BOD 22-01 mitigations (including for cloud services), or discontinue use by the catalog due date. Until patched, follow Microsoft's mitigation guidance from vendor advisories and monitor for updates, since specific affected builds and the exploited security feature have not been detailed in the available data.

8.8
group max
26% KEV
  • Microsoft Windows
mass≈1+ billion Windows devices
CVE-2026-21514
Actively Exploited Security Feature Bypass in Microsoft Word (CVE-2026-21514)

CVE-2026-21514 is a security feature bypass in Microsoft Word caused by the application relying on untrusted inputs when making a security decision (CWE-807). The flaw carries a local attack vector with a user-interaction requirement, so it is most plausibly triggered when a user opens attacker-supplied content, such as a crafted document, on a system running Word. A local, unauthorized attacker who exploits it can circumvent a Word security feature, with high-impact confidentiality, integrity, and availability effects on the local system; bypasses of this type are commonly chained with other flaws for deeper compromise. Any organization running Microsoft 365 Apps or Office Long Term Servicing Channel (LTSC) is affected. CISA added the bug to the Known Exploited Vulnerabilities catalog on 2026-02-10, confirming exploitation in the wild, though no public proof-of-concept is known and EPSS currently estimates a 1.5% chance of exploitation in the next 30 days (73rd percentile).

Do: Apply the February 2026 Patch Tuesday security updates from Microsoft for Microsoft 365 Apps and Office LTSC immediately; fixed version numbers were not provided in the source data, so use Microsoft's release guidance to confirm builds. Because the flaw is in CISA KEV, federal agencies must satisfy BOD 22-01 by applying the update (or directed mitigations) within the mandated weeks, and all organizations should prioritize endpoints that open untrusted documents. Until patched, consider Office hardening such as marking files from the internet as untrusted in Word and watching for anomalous document-driven local activity.

7.82% KEV
  • Microsoft 365 Apps
  • Microsoft Office Long Term Servicing Channel (LTSC)
  • Microsoft Office (broadly listed by CISA)
masshundreds of millions of users (Word is bundled in Microsoft 365 and Office across most enterprise desktop fleets)
CVE-2026-21531
Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.

Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.

NVD description · AI analysis pending
9.82%
  • microsoft azure conversation authoring client library
CVE-2026-24300
Azure Front Door Elevation of Privilege Vulnerability

Azure Front Door Elevation of Privilege Vulnerability

NVD description · AI analysis pending
9.81%
  • microsoft azure front door
Full article684 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Microsoft said three of the exploited vulnerabilities were publicly known, suggesting attackers already had details about the defects prior to Tuesday’s release.

Listen to this article

0:00

Learn more.

(Photo by John Smith/VIEWpress/Getty Images)

Microsoft’s latest security update is littered with zero-day vulnerabilities, actively exploited defects that account for more than 10% of the total CVEs the vendor addressed in this month’s Patch Tuesday update.

The vendor addressed 59 vulnerabilities affecting its various products for business operations and underlying systems, including six defects that were actively exploited prior to Microsoft’s release of its monthly batch of patches. Microsoft said three of the exploited vulnerabilities were publicly known, suggesting attackers already had details about the defects prior to Tuesday’s release.

“The number of bugs under active attack is extraordinarily high,” Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, said in a blog post.

Microsoft’s February security update matched the high it reached last March when it disclosed six actively exploited zero-days.

The highest rated zero-days, a pair of defects with CVSS ratings of 8.8, include CVE-2026-21510 affecting Windows Shell 8.8 and CVE-2026-21513 affecting Internet Explorer. Both vulnerabilities require user interaction and could allow attackers to execute code.

Mike Walters, president and co-founder of Action1, said CVE-2026-21510 is caused by a protection mechanism failure that allows an attacker to bypass Windows protections by tricking a user to click on a single malicious link.

“Functional exploit techniques exist, demonstrating reliable bypass of Windows Shell and SmartScreen security prompts through crafted links or shortcut files. No privileges are required by the attacker, making this vulnerability highly attractive for phishing-based attacks,” Walters said in a blog post.

The remaining zero-days include three defects with CVSS ratings of 7.8: CVE-2026-21514 affecting Microsoft Office Word, CVE-2026-21519 affecting Desktop Window Manager, and CVE-2026-21533 affecting Windows Remote Desktop. CVE-2026-21525, which affects Windows Remote Access Connection Manager, has a CVSS rating of 6.2.

The Cybersecurity and Infrastructure Security Agency added all six of the zero-days to its known exploited vulnerabilities catalog Tuesday.

Three of the vulnerabilities — CVE-2026-21510, CVE-2026-21513 and CVE-2026-21514 — bear strong similarities as security feature bypasses, Satnam Narang, senior staff research engineer at Tenable, said in an email.

These security features protect users from opening malicious files, he said. “Users have grown accustomed to receiving these alerts, so when vulnerabilities can bypass those protection mechanisms, users are more at risk of compromise.”

Microsoft disclosed two critical vulnerabilities with CVSS ratings of 9.8 this month, including CVE-2026-21531 affecting Azure SDK and CVE-2026-24300 affecting Azure Front Door.

The vast majority of defects Microsoft addressed this month fell into the high-severity category, accounting for 43 vulnerabilities total. The vendor described five of those vulnerabilities as more likely to be exploited.

The full list of vulnerabilities addressed this month is available in Microsoft’s Security Response Center.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-patch-tuesday-february-2026/