Microsoft’s February update fixes more than 50 flaws, including six zero-days

THE BRIEF
Krebs on Security reports that Microsoft’s February 2026 security release addresses more than 50 security holes in Windows and other software. The update includes six zero-day vulnerabilities that, according to the report, attackers are already exploiting in the wild. One, CVE-2026-21510, is a Windows Shell security feature bypass: a single click on a malicious link can bypass Windows protections and run attacker-controlled content without warning or consent dialogs. The issue affects all currently supported Windows versions. CVE-2026-21513 is described as a security bypass affecting MSHTML, while CVE-2026-21514 is a related bypass in Microsoft Word. Another listed zero-day, CVE-2026-21533, permits local attackers to elevate privileges to SYSTEM level through Windows Remote Desktop. The supplied report identifies these vulnerabilities as part of Microsoft’s February 10 release and highlights active exploitation as the reason for urgent attention. Organizations should use Microsoft’s updates and vulnerability details to determine applicable remediation priorities.
WHY IT MATTERS
This release combines a broad patch set with six zero-days reportedly exploited in the wild, increasing the importance of timely assessment. CVE-2026-21510 is especially notable because the report says a single click on a malicious link can bypass Windows protections and execute attacker-controlled content without warning or consent dialogs. The affected Windows Shell issue applies across supported Windows versions, while other listed flaws involve MSHTML, Word, and Windows Remote Desktop privilege elevation. Teams need to distinguish the issues relevant to their environments and prioritize Microsoft’s fixes based on exposure and exploitation status.
WHO SHOULD CARE
Windows administrators, endpoint-security teams, vulnerability-management leaders, and organizations running Microsoft Word or Windows Remote Desktop should review the February release. Security leadership should pay particular attention to the reported active exploitation of six zero-days.
WHAT TO DO NOW
- Inventory supported Windows systems and related Microsoft software, then apply the February 2026 security updates according to your change procedures.
- Prioritize assessment and remediation for CVE-2026-21510, CVE-2026-21513, CVE-2026-21514, and CVE-2026-21533, while reviewing the remaining zero-days in the release.
- Review whether Windows Shell, MSHTML, Microsoft Word, or Windows Remote Desktop are present and exposed in your environment.