Microsoft released its February 2026 Patch Tuesday security updates, addressing 54–58 vulnerabilities across Windows and other Microsoft products, including six zero-days that were publicly disclosed and/or actively exploited prior to patch availability. Reported zero-days include CVE-2026-21514 (Office Word security feature bypass), CVE-2026-21513 (MSHTML security feature bypass), CVE-2026-21510 (Windows Shell security feature bypass), CVE-2026-21533 (Windows Remote Desktop Services elevation of privilege), CVE-2026-21525 (Windows Remote Access Connection Manager DoS), and CVE-2026-21519 (Desktop Window Manager elevation of privilege). The broader release spans common bug classes such as RCE, EoP, information disclosure, spoofing, DoS, and security feature bypass, with multiple Critical issues also called out, including Azure Compute Gallery flaws impacting ACI Confidential Containers (CVE-2026-23655, CVE-2026-21522).
As part of the February Windows updates, Microsoft also began a phased rollout of updated Secure Boot certificates to replace the original 2011 certificates ahead of their expiration in late June 2026, using “targeting data” and “successful update signals” to control deployment. Windows 11 cumulative updates (including KB5077181 and KB5075941) were released as mandatory Patch Tuesday packages for supported Windows 11 versions, bundling the security fixes alongside additional reliability and feature changes. Separately, Adobe issued February security bulletins covering 44 CVEs across multiple Creative Cloud products; those Adobe issues were not listed as publicly known or under active attack at release.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos announced updated Snort rules to help detect exploitation attempts related to some of the vulnerabilities addressed in Microsoft's February 2026 Patch Tuesday release. The guidance accompanied Talos' review of the month's prominent Microsoft vulnerabilities.
On 2026-02-10, the Canadian Centre for Cyber Security published advisory AV26-111 summarizing Microsoft's February security updates. The advisory highlighted the six actively exploited CVEs and urged administrators to review Microsoft's guidance and apply the updates.
Following Microsoft's February 2026 Patch Tuesday release, CISA added all six actively exploited zero-day vulnerabilities to its Known Exploited Vulnerabilities catalog. This elevated the urgency for federal agencies and other defenders to prioritize remediation.
On 2026-02-10, Microsoft released mandatory Windows 11 cumulative updates KB5077181 and KB5075941 for versions 25H2/24H2 and 23H2. The updates delivered the February security fixes along with quality improvements and new features, and Microsoft said it was not aware of new issues at release.
As part of the February 2026 updates, Microsoft started a phased deployment of updated Secure Boot certificates to replace expiring 2011 certificates. The rollout used device targeting data and successful-update signals to control deployment.
The February 2026 Patch Tuesday release fixed six zero-day vulnerabilities that Microsoft said were actively exploited in the wild, including flaws in Windows Shell/SmartScreen, MSHTML, Microsoft Word, Desktop Window Manager, Remote Desktop Services, and Remote Access Connection Manager. Three of the zero-days were also publicly disclosed before patches became available.
On 2026-02-10, Microsoft published its February 2026 Patch Tuesday security updates, addressing roughly 54-59 vulnerabilities across Windows, Office, Azure, Exchange, developer tools, and other products. The release included multiple critical issues and required customer action to apply the fixes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcecyberscoop.com
Open sourcecyber.gc.ca
Open sourcekrebsonsecurity.com
Open sourceblog.talosintelligence.com
Open sourcebleepingcomputer.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.