Microsoft Patch Tuesday security updates for February 2026 fix six actively exploited zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-21510 | Security Feature Bypass in Microsoft Windows Shell Actively Exploited (CVE-2026-21510) Microsoft Windows Shell contains a protection mechanism failure (CWE-693) that allows an unauthorized attacker to bypass a security feature, which CISA notes can be reached over a network. Successful exploitation defeats a Windows defense-in-depth control, weakening protections an attacker would otherwise have to evade as part of a broader intrusion; the available data does not describe a code-execution or privilege-escalation gain. Any system running Microsoft Windows falls within CISA's published affected scope, and specific version ranges have not been enumerated in the available data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-10, confirming exploitation in the wild, and its EPSS score of 26.2% (98th percentile) signals elevated near-term exploitation risk; ransomware use is unknown and no public proof-of-concept is known. Do: Apply Microsoft's applicable Windows security update through Windows Update/WSUS or your patch-management process as soon as practical, prioritizing internet-exposed and high-value systems; because the issue is in CISA's KEV catalog (added 2026-02-10), U.S. federal agencies must apply the vendor fix, applicable BOD 22-01 mitigations (including for cloud services), or discontinue use by the catalog due date. Until patched, follow Microsoft's mitigation guidance from vendor advisories and monitor for updates, since specific affected builds and the exploited security feature have not been detailed in the available data. | 8.8 group max | 26% | KEV |
| mass≈1+ billion Windows devices | |
| CVE-2026-21514 | Actively Exploited Security Feature Bypass in Microsoft Word (CVE-2026-21514) CVE-2026-21514 is a security feature bypass in Microsoft Word caused by the application relying on untrusted inputs when making a security decision (CWE-807). The flaw carries a local attack vector with a user-interaction requirement, so it is most plausibly triggered when a user opens attacker-supplied content, such as a crafted document, on a system running Word. A local, unauthorized attacker who exploits it can circumvent a Word security feature, with high-impact confidentiality, integrity, and availability effects on the local system; bypasses of this type are commonly chained with other flaws for deeper compromise. Any organization running Microsoft 365 Apps or Office Long Term Servicing Channel (LTSC) is affected. CISA added the bug to the Known Exploited Vulnerabilities catalog on 2026-02-10, confirming exploitation in the wild, though no public proof-of-concept is known and EPSS currently estimates a 1.5% chance of exploitation in the next 30 days (73rd percentile). Do: Apply the February 2026 Patch Tuesday security updates from Microsoft for Microsoft 365 Apps and Office LTSC immediately; fixed version numbers were not provided in the source data, so use Microsoft's release guidance to confirm builds. Because the flaw is in CISA KEV, federal agencies must satisfy BOD 22-01 by applying the update (or directed mitigations) within the mandated weeks, and all organizations should prioritize endpoints that open untrusted documents. Until patched, consider Office hardening such as marking files from the internet as untrusted in Word and watching for anomalous document-driven local activity. | 7.8 | 2% | KEV |
| masshundreds of millions of users (Word is bundled in Microsoft 365 and Office across most enterprise desktop fleets) |
Full article336 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
February 10, 2026

Microsoft Patch Tuesday security updates for February 2026 fix six actively exploited zero-day vulnerabilities.
Microsoft Patch Tuesday security updates for February 2026 fix 58 new security flaws across Windows, Office, Azure, Edge, Exchange, Hyper-V, WSL, and other components, rising to 62 CVEs when third-party updates are included. Five vulnerabilities are Critical, two Moderate, and most are rated Important. What stands out is that six flaws addressed this month are actively exploited in the wild, three of them publicly known.
Below are the six zero-day vulnerabilities addressed by the IT giant:
- CVE-2026-21510 (CVSS score of 7.5 – High)
A Windows SmartScreen and Shell prompt bypass that allows attackers to evade security warnings by tricking users into opening a crafted malicious link or shortcut file. - CVE-2026-21513 (CVSS score of 8.8 – High)
An Internet Explorer security control bypass that can lead to code execution when a victim opens a malicious HTML page or LNK file. - CVE-2026-21514 (CVSS score of 8.1 – High)
A Microsoft 365 and Office flaw that bypasses OLE security mitigations, enabling malicious activity when a specially crafted Office document is opened. - CVE-2026-21519 (CVSS score of 7.8 – High)
A Windows Desktop Window Manager vulnerability that enables local privilege escalation and elevated system access. - CVE-2026-21525 (CVSS score of 6.5 – Medium)
A Windows Remote Access Connection Manager bug that can be abused by a local attacker to cause a denial-of-service condition. - CVE-2026-21533 (CVSS score of 8.8 – High)
A Windows Remote Desktop Services vulnerability that allows attackers to escalate privileges to SYSTEM.
Microsoft labeled CVE-2026-21510, CVE-2026-21514 and CVE-2026-21513 as “publicly disclosed”.
Microsoft credited Google Threat Intelligence Group, its internal security teams, and an anonymous researcher for discovering CVE-2026-21510 and CVE-2026-21514, while Microsoft and GTIG reported the vulnerability CVE-2026-21513.
The full list of CVEs addressed by the Microsoft Patch Tuesday security update for February 2026 is available here.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Patch Tuesday)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/187848/uncategorized/microsoft-patch-tuesday-security-updates-for-february-2026-fix-six-actively-exploited-zero-days.html