Microsoft Patches Six Zero-Day Vulnerabilities in February 2026 Update
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
On February 2026, Microsoft issued updates to fix more than 50 security vulnerabilities in its Windows operating systems and other software. This includes six zero-day vulnerabilities that are currently being exploited in the wild. The vulnerabilities include CVE-2026-21510, a security feature bypass in Windows Shell, and CVE-2026-21513, which targets MSHTML, the engine of the default Windows web browser.
Another critical flaw, CVE-2026-21514, is a related security bypass in Microsoft Word. Additionally, CVE-2026-21533 allows local attackers to elevate their privileges to SYSTEM level in Windows Remote Desktop Services. CVE-2026-21519 is an elevation of privilege flaw in the Desktop Window Manager, while CVE-2026-21525 poses a denial-of-service risk in the Windows Remote Access Connection Manager.
Chris Goettl from Ivanti noted that Microsoft has also issued several out-of-band security updates since January’s Patch Tuesday, including a fix for a credential prompt failure in remote desktop connections. On January 26, Microsoft patched another zero-day vulnerability in Microsoft Office.
Furthermore, this month’s Patch Tuesday addresses remote code execution vulnerabilities affecting GitHub Copilot and various integrated development environments (IDEs) such as VS Code and JetBrains products. The relevant CVEs include CVE-2026-21516, CVE-2026-21523, and CVE-2026-21256.
These AI vulnerabilities stem from command injection flaws that can be exploited through prompt injection, potentially allowing malicious code execution. Developers are particularly at risk as they often handle sensitive data like API keys.
Organizations should ensure that developers understand these risks and apply least-privilege principles to limit potential damage if secrets are compromised. The SANS Internet Storm Center provides a detailed breakdown of the fixes indexed by severity and CVSS score, which can assist enterprise Windows admins in testing patches.
As a precaution, users should back up their data regularly and monitor for any issues when installing these updates.
- CVE-2026-21510: A security feature bypass vulnerability in Windows Shell that allows malicious links to bypass protections.
- CVE-2026-21513: A security bypass bug targeting MSHTML, the web browser engine in Windows.
- CVE-2026-21514: A related security feature bypass in Microsoft Word.
- CVE-2026-21533: A flaw that allows local attackers to gain SYSTEM-level access in Windows Remote Desktop Services.
- CVE-2026-21519: An elevation of privilege flaw in the Desktop Window Manager.
- CVE-2026-21525: A denial-of-service vulnerability in the Windows Remote Access Connection Manager.
- CVE-2026-21516: A remote code execution vulnerability affecting GitHub Copilot.
- CVE-2026-21523: A related remote code execution vulnerability in IDEs.
- CVE-2026-21256: Another remote code execution vulnerability affecting integrated development environments.
Key Takeaways
- Update your Windows operating system and software immediately to protect against the newly patched vulnerabilities.
- Regularly back up your data to mitigate potential data loss from attacks.
- Educate developers about the risks associated with AI vulnerabilities and implement least-privilege access controls.
- Monitor for any issues or errors during the installation of the updates.
- Stay informed about future security updates and vulnerabilities by following trusted cybersecurity sources.
Key Terms & Concepts
- Zero-Day Vulnerability: In this article, a zero-day vulnerability refers to a security flaw that is exploited by attackers before the vendor has released a fix.
- CVE: CVE stands for Common Vulnerabilities and Exposures, which is a list of publicly known cybersecurity vulnerabilities.
- Remote Code Execution: Remote code execution is a type of vulnerability that allows an attacker to run arbitrary code on a remote system.
- Privilege Escalation: Privilege escalation is a security flaw that allows an attacker to gain elevated access to resources that are normally protected from the user.
- Denial-of-Service: Denial-of-service refers to an attack that aims to make a service unavailable to its intended users.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.