Microsoft Patch Tuesday security updates for February 2026 fix six actively exploited zero-days

2 Min Read

Microsoft Patch Tuesday security updates for February 2026 fix six actively exploited zero-day vulnerabilities.

Microsoft Patch Tuesday security updates for February 2026 fix 58 new security flaws across Windows, Office, Azure, Edge, Exchange, Hyper-V, WSL, and other components, rising to 62 CVEs when third-party updates are included. Five vulnerabilities are Critical, two Moderate, and most are rated Important. What stands out is that six flaws addressed this month are actively exploited in the wild, three of them publicly known.

- Advertisement -

Below are the six zero-day vulnerabilities addressed by the IT giant:

  • CVE-2026-21510 (CVSS score of 7.5 – High)
    A Windows SmartScreen and Shell prompt bypass that allows attackers to evade security warnings by tricking users into opening a crafted malicious link or shortcut file.
  • CVE-2026-21513 (CVSS score of 8.8 – High)
    An Internet Explorer security control bypass that can lead to code execution when a victim opens a malicious HTML page or LNK file.
  • CVE-2026-21514 (CVSS score of 8.1 – High)
    A Microsoft 365 and Office flaw that bypasses OLE security mitigations, enabling malicious activity when a specially crafted Office document is opened.
  • CVE-2026-21519 (CVSS score of 7.8 – High)
    A Windows Desktop Window Manager vulnerability that enables local privilege escalation and elevated system access.
  • CVE-2026-21525 (CVSS score of 6.5 – Medium)
    A Windows Remote Access Connection Manager bug that can be abused by a local attacker to cause a denial-of-service condition.
  • CVE-2026-21533 (CVSS score of 8.8 – High)
    A Windows Remote Desktop Services vulnerability that allows attackers to escalate privileges to SYSTEM.

Microsoft labeled CVE-2026-21510, CVE-2026-21514 and CVE-2026-21513 as “publicly disclosed”.


What do you think? Post a comment.


Microsoft credited Google Threat Intelligence Group, its internal security teams, and an anonymous researcher for discovering CVE-2026-21510 and CVE-2026-21514, while Microsoft and GTIG reported the vulnerability CVE-2026-21513.

- Advertisement -

EXPLORE MORE

Wanted: Suspect Naseem Sills for Homicide in the 12th District

Philadelphia Police, Homicide Detectives are seeking the public’s help in locating Naseem…

From the Ashes of Empire to the Fire of the Bubble: How the War Economy Built Modern Japan

In August 1945, General Douglas MacArthur stepped off his aircraft at Atsugi…

PATRIOT MISSILE SHORTAGE: FOUR-YEAR DELAY LOOMS FOR DEFENSE GIANT ORDERS

WASHINGTON — Pentagon planners and foreign military attachés face a sobering industrial…

Is Callsign: Sky Shaker the Next Ace Combat?

Big AAA studios are restructuring, but the solo developer behind Callsign: Sky…

Wanted: Suspect for Theft of a Dog in the 35th District [UPDATE]

***THE VICTIM’S DOG HAS BEEN RETURNED BY A GOOD SAMARITAN AND THIS…

Wendy’s Announces ‘Wendy’ Has Been Quietly ‘Replaced’ by Newer, Shorter Wendy

DUBLIN, OH — In a major rebranding move, Wendy’s International announced Friday…

The full list of CVEs addressed by the Microsoft Patch Tuesday security update for February 2026 is available here.

Pierluigi Paganini



Share This Article

Russia Hits Kiev Ammo Dump Next To Homes; Ukraine Admits 90% Of Retail Food Logistics Wrecked

A Russian drone struck a Ukrainian Defense Forces ammunition…

US Steps Up Africa Push As China Expands Economic, Security Footprint

Authored by Arthur Zhang via The Epoch Times, The…

US-Backed SDF Leader Joins Sharaa Regime As Presidential Advisor After Kurdish Force Dissolved

Via The Cradle Self-proclaimed Syrian President Ahmad al-Sharaa has…

Cassandra Peterson: Life Beyond the Bouffant for the Queen of Halloween

For over four decades, Cassandra Peterson has reigned supreme…

Kurt Weldon’s 9/11 Bombshell on Jimmy Dore

Former Republican Congressman Kurt Weldon—who served Pennsylvania's 7th district…

“Black Power — It’s About Goddamn Time!”

New Black Panther Party national chairwoman Krystal Muhammad celebrates…

Iran's Ghalibaf Declares Persian Gulf Oil Flows For 'All Or None'

Via The Cradle Iranian Parliament Speaker Mohammad Bagher Ghalibaf…

CONVERSATION

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted