Microsoft Addresses 59 Vulnerabilities Including Six Actively Exploited Zero-Days
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
On February 10, 2026, Microsoft issued security updates addressing 59 vulnerabilities across its software, including six that are actively exploited. The vulnerabilities include five rated Critical and 52 rated Important, with the most severe being CVE-2026-21510 and CVE-2026-21513, both with a CVSS score of 8.8. These vulnerabilities allow unauthorized attackers to bypass security features in Windows Shell and the MSHTML Framework, respectively.
Additionally, CVE-2026-21514, CVE-2026-21519, CVE-2026-21525, and CVE-2026-21533 are also critical vulnerabilities that could allow local privilege escalation or denial of service. Microsoft and Google Threat Intelligence Group (GTIG) discovered the first three flaws, which were publicly known at the time of release.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added these six vulnerabilities to its Known Exploited Vulnerabilities catalog, mandating that Federal Civilian Executive Branch agencies apply the necessary patches by March 3, 2026. This highlights the urgency of addressing these vulnerabilities to protect sensitive systems.
Microsoft is also updating its Secure Boot certificates, which will replace the original 2011 certificates expiring in June 2026. Failure to receive the new certificates could lead to a degraded security state, limiting future protections against boot-level vulnerabilities.
In addition to these updates, Microsoft is enhancing Windows security through initiatives like Windows Baseline Security Mode and User Transparency and Consent, aiming to improve runtime integrity safeguards and user awareness regarding app permissions.
Why These Vulnerabilities Matter
The vulnerabilities pose significant risks as they can allow attackers to elevate privileges or bypass security measures, potentially leading to full domain compromise. Organizations and users must be vigilant in applying updates and monitoring for signs of exploitation.
Understanding these vulnerabilities and their implications is crucial for maintaining security. Users should be aware of the types of files that could exploit these vulnerabilities, such as crafted HTML or Microsoft Office files.
- CVE-2026-21510 – A protection mechanism failure in Windows Shell that allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-21513 – A protection mechanism failure in MSHTML Framework that allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-21514 – A reliance on untrusted inputs in Microsoft Office Word that allows an unauthorized attacker to bypass a security feature locally.
- CVE-2026-21519 – An access of resource using incompatible type in the Desktop Window Manager that allows an authorized attacker to elevate privileges locally.
- CVE-2026-21525 – A null pointer dereference in Windows Remote Access Connection Manager that allows an unauthorized attacker to deny service locally.
- CVE-2026-21533 – An improper privilege management in Windows Remote Desktop that allows an authorized attacker to elevate privileges locally.
Key Takeaways
- Ensure all Microsoft software is updated to the latest version to protect against the newly patched vulnerabilities.
- Monitor for any unusual activity on systems that may indicate exploitation attempts of these vulnerabilities.
- Educate users about the risks of opening suspicious files, especially HTML and Microsoft Office documents.
- Review and enhance security protocols to mitigate the risk of privilege escalation attacks.
- Stay informed about updates from CISA regarding known exploited vulnerabilities and compliance requirements.
Key Terms & Concepts
- CVE: In this article, CVE refers to a Common Vulnerabilities and Exposures identifier used to catalog security vulnerabilities.
- CVSS: CVSS stands for Common Vulnerability Scoring System, which assigns severity scores to vulnerabilities based on their impact.
- Zero-Day: A zero-day refers to a security flaw that is exploited before the vendor has released a fix.
- Privilege Escalation: Privilege escalation is a type of attack where an unauthorized user gains elevated access to resources.
- Secure Boot: Secure Boot is a security standard that ensures a device boots using only software that is trusted by the manufacturer.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.