ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Microsoft Fixes Six Zero Day Vulnerability in February Patch Tuesday

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-0488
An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical

An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on confidentiality, integrity, and availability.

NVD description · AI analysis pending
9.9<1%
  • sap netweaver application server abap
  • sap s\/4hana
  • sap webclient ui framework
CVE-2026-0509
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the req

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain cases. This can result in a high impact on integrity and availability, and no impact on the confidentiality of the application.

NVD description · AI analysis pending
9.6<1%
  • sap netweaver as abap kernel
  • sap netweaver as abap krnl64nuc
  • sap netweaver as abap krnl64uc
CVE-2026-21510
+4 in the same advisory: …21513 …21533 …21519 …21525
Security Feature Bypass in Microsoft Windows Shell Actively Exploited (CVE-2026-21510)

Microsoft Windows Shell contains a protection mechanism failure (CWE-693) that allows an unauthorized attacker to bypass a security feature, which CISA notes can be reached over a network. Successful exploitation defeats a Windows defense-in-depth control, weakening protections an attacker would otherwise have to evade as part of a broader intrusion; the available data does not describe a code-execution or privilege-escalation gain. Any system running Microsoft Windows falls within CISA's published affected scope, and specific version ranges have not been enumerated in the available data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-10, confirming exploitation in the wild, and its EPSS score of 26.2% (98th percentile) signals elevated near-term exploitation risk; ransomware use is unknown and no public proof-of-concept is known.

Do: Apply Microsoft's applicable Windows security update through Windows Update/WSUS or your patch-management process as soon as practical, prioritizing internet-exposed and high-value systems; because the issue is in CISA's KEV catalog (added 2026-02-10), U.S. federal agencies must apply the vendor fix, applicable BOD 22-01 mitigations (including for cloud services), or discontinue use by the catalog due date. Until patched, follow Microsoft's mitigation guidance from vendor advisories and monitor for updates, since specific affected builds and the exploited security feature have not been detailed in the available data.

8.8
group max
26% KEV
  • Microsoft Windows
mass≈1+ billion Windows devices
CVE-2026-21514
Actively Exploited Security Feature Bypass in Microsoft Word (CVE-2026-21514)

CVE-2026-21514 is a security feature bypass in Microsoft Word caused by the application relying on untrusted inputs when making a security decision (CWE-807). The flaw carries a local attack vector with a user-interaction requirement, so it is most plausibly triggered when a user opens attacker-supplied content, such as a crafted document, on a system running Word. A local, unauthorized attacker who exploits it can circumvent a Word security feature, with high-impact confidentiality, integrity, and availability effects on the local system; bypasses of this type are commonly chained with other flaws for deeper compromise. Any organization running Microsoft 365 Apps or Office Long Term Servicing Channel (LTSC) is affected. CISA added the bug to the Known Exploited Vulnerabilities catalog on 2026-02-10, confirming exploitation in the wild, though no public proof-of-concept is known and EPSS currently estimates a 1.5% chance of exploitation in the next 30 days (73rd percentile).

Do: Apply the February 2026 Patch Tuesday security updates from Microsoft for Microsoft 365 Apps and Office LTSC immediately; fixed version numbers were not provided in the source data, so use Microsoft's release guidance to confirm builds. Because the flaw is in CISA KEV, federal agencies must satisfy BOD 22-01 by applying the update (or directed mitigations) within the mandated weeks, and all organizations should prioritize endpoints that open untrusted documents. Until patched, consider Office hardening such as marking files from the internet as untrusted in Word and watching for anomalous document-driven local activity.

7.82% KEV
  • Microsoft 365 Apps
  • Microsoft Office Long Term Servicing Channel (LTSC)
  • Microsoft Office (broadly listed by CISA)
masshundreds of millions of users (Word is bundled in Microsoft 365 and Office across most enterprise desktop fleets)
Full article468 words · extracted from infosecurity-magazine.com · click to collapse

System administrators are likely to have a busy February after Microsoft released updates to fix six actively exploited zero-day vulnerabilities, three of which have been publicly disclosed.

The zero-days are as follows:

  • CVE-2026-21510 is a security feature bypass vulnerability in Windows Shell which enables unauthorized attackers to circumvent Windows SmartScreen and security prompt protections by tricking victims into clicking on a malicious link
  • CVE-2026-21513 is a security feature bypass vulnerability in the Microsoft MSHTML Framework, which is used by Windows and various applications to render HTML content. “A crafted file can silently bypass Windows security prompts and trigger dangerous actions with a single click,” warned Action1 director of vulnerability research, Jack Bicer
  • CVE-2026-21514 is a security feature bypass vulnerability in Microsoft Word. Exploitation requires no privileges but the victim must open a malicious document
  • CVE-2026-21519 is an elevation of privilege (EoP) flaw in the Windows Desktop Window Manager (DWM) which allows attackers turn basic access into full system control. It’s unclear how it is being exploited
  • CVE-2026-21525 is a denial-of-service vulnerability affecting the Windows Remote Access Connection Manager. “Exploitation is local, requires no privileges, and does not rely on user interaction,” explained Action1 president, Mike Walters. “An attacker with basic local access can repeatedly trigger the flaw to cause persistent service disruption.”
  • CVE-2026-21533 is another EoP vulnerability in Windows Remote Desktop Services. Exploitation is local, requires only low privileges, and does not need user interaction, noted Bicer

Read more on Patch Tuesday: Microsoft Fixes Three Zero-Days on Busy Patch Tuesday.

In total this month, most CVEs disclosed by Microsoft were EoP (25), followed by remote code execution (12), spoofing (7), information disclosure (6) and security feature bypass (5).

None of the actively exploited vulnerabilities are rated critical. In fact, only five CVEs out of the 58 patched this month are critical.

SAP Adds to the Patch Load

Elsewhere, SAP released 26 new security “notes” yesterday, and one update to a previously released note.

The two most serious CVEs include a missing authorization check vulnerability (CVE-2026-0509) in SAP NetWeaver Application Server ABAP and ABAP Platform – which has a CVSS score of 9.6.

The second (CVE-2026-0488) is a code injection vulnerability in SAP CRM and SAP S/4HANA (Scripting Editor), which has a CVSS score of 9.9.

Pathlock SAP security analyst, Jonathan Stross, explained that the affected systems are commonly used by call center agents and CRM support staff.

“A realistic attack chain could start from attackers compromising a standard CRM user through phishing, password reuse, or endpoint compromise. Then, the attacker accesses the Scripting Editor-related functionality and leverages the generic call flaw,” he continued.

“Finally, they execute unauthorized database-level actions (SQL), resulting in broad control. Once there, an attacker can compromise the database, steal or modify data, and cause operational disruption by manipulating CRM/S/4 data at the persistence layer.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-six-zero-day-feb-2026/