Microsoft February 2026 Patch Tuesday Includes Key OOB Fixes and Updates
- Securityish
- Tools & Best Practices
Quick Summary
The Securityish Brief
February 2026 Patch Tuesday will see Microsoft releasing important updates, including three rounds of out-of-band (OOB) patches. These patches will address issues from the January updates, which affected Windows 10, Windows 11, and various server versions. The first OOB patch, released on January 17th, fixed credential prompt failures during remote desktop connections, impacting all supported OS versions.
The second OOB patch, issued on January 24th, resolved issues with Microsoft Outlook Classic that prevented reading or writing to .pst files stored in OneDrive. The final OOB patch on January 26th addressed a critical zero-day vulnerability, CVE-2026-21509, in Microsoft Office, which could allow unauthorized access if a malicious Office file is opened.
Additionally, Microsoft has announced a phased disablement of the NTLM authentication protocol, which has been in use since 1993. This transition will occur in three phases, starting with identifying where NTLM is still in use and recommending advanced NTLM auditing. The final phase will see NTLM disabled by default, requiring explicit re-enablement if necessary.
In terms of other software updates, users can expect performance and security updates for Microsoft Office, potential updates for Adobe Creative Cloud apps, and major OS updates from Apple. Google Chrome and Mozilla Firefox are also expected to release new versions soon.
Implications for Users and Organizations
These updates highlight the ongoing need for vigilance regarding software vulnerabilities. Users should ensure they apply patches promptly to protect against exploits, especially for critical applications like Microsoft Office, which has seen active exploitation of vulnerabilities.
Organizations must prepare for the phased disablement of NTLM by auditing their systems and transitioning to Kerberos where possible. This proactive approach can significantly enhance security posture and reduce reliance on outdated protocols.
Finally, with reports of vulnerabilities in widely used applications like WinRAR and Notepad++, users should regularly review their security settings and update software to mitigate risks from potential exploits.
- Microsoft Windows 11 and Server 2025 updates addressed 92 vulnerabilities in January 2026.
- OOB patches released in January fixed credential prompt failures and Outlook issues.
- CVE-2026-21509 is a zero-day vulnerability in Microsoft Office requiring immediate attention.
- NTLM phased disablement will enhance security but requires user action to transition.
- Expect updates for Adobe Creative Cloud and Google Chrome in February 2026.
Key Takeaways
- Regularly check for and apply Microsoft updates to ensure your systems are secure.
- Audit your environment to identify and replace NTLM with Kerberos where possible.
- Review your security settings for applications like WinRAR and Notepad++ to prevent exploitation.
- Monitor for updates from Adobe and Google to keep your software current.
- Educate users about the risks of opening unknown Office files to avoid zero-day vulnerabilities.
Key Terms & Concepts
- OOB patches: Out-of-band patches are updates released outside the regular schedule to address critical issues or vulnerabilities.
- CVE-2026-21509: CVE-2026-21509 is a zero-day vulnerability in Microsoft Office that allows unauthorized access when a malicious file is opened.
- NTLM: New Technology LAN Manager (NTLM) is an outdated authentication protocol that Microsoft plans to phase out in favor of more secure methods.
- Kerberos: Kerberos is a secure authentication protocol that supersedes NTLM and is recommended for use in modern systems.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.