CISA added six Microsoft zero-day vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after evidence of active exploitation in the wild, triggering mandatory remediation timelines for U.S. Federal Civilian Executive Branch agencies under BOD 22-01 and prompting broader patch prioritization across enterprises. The vulnerabilities span multiple Microsoft components, including MSHTML and Microsoft Word, and are positioned as high-risk initial access and post-exploitation enablers commonly leveraged in phishing-driven intrusion chains and follow-on activity such as lateral movement and ransomware operations.
Microsoft’s Security Update Guide entries provide technical details for several of the KEV-listed issues, including CVE-2026-21513 (MSHTML Framework Security Feature Bypass, CVSS 8.8, AV:N/AC:L/PR:N/UI:R) and CVE-2026-21514 (Microsoft Word Security Feature Bypass, CVSS 7.8, AV:L/AC:L/PR:N/UI:R), both consistent with document/web-content delivery scenarios. Separately, Microsoft also patched CVE-2026-21525 (Windows Remote Access Connection Manager / RasMan Denial of Service, CVSS 6.2, AV:L/AC:L/PR:N/UI:N), described as a NULL pointer dereference that can be triggered by a local, unauthenticated attacker to crash RasMan and disrupt remote connectivity; reporting indicates exploitation was detected prior to disclosure and fixes were shipped via Patch Tuesday updates for multiple Windows and Windows Server versions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-02-11, CISA added six actively exploited Microsoft vulnerabilities to its Known Exploited Vulnerabilities catalog following Microsoft's disclosures and patches. The agency directed U.S. federal civilian agencies to remediate them under Binding Operational Directive 22-01 and urged broader prioritization of patching.
On 2026-02-10, Microsoft published advisories for CVE-2026-21513 and CVE-2026-21514, security feature bypass vulnerabilities in the MSHTML Framework and Microsoft Word, respectively. Reporting indicated these flaws were among the zero-days with public exploit evidence addressed in the February Patch Tuesday release.
Microsoft's February 2026 advisories identified CVE-2026-21525 as a denial-of-service vulnerability in Windows Remote Access Connection Manager that had been exploited in the wild before disclosure. The flaw could let an attacker with local access crash the RasMan service and disrupt remote connectivity.
On 2026-02-10, Microsoft published security updates for multiple actively exploited zero-day vulnerabilities, including CVE-2026-21510, CVE-2026-21513, CVE-2026-21514, and CVE-2026-21525. The patched issues affected Windows Shell, MSHTML, Microsoft Word, Remote Access Connection Manager, and other Microsoft components.
The 0patch research team at ACROS Security discovered and reported CVE-2026-21525, a NULL pointer dereference denial-of-service flaw in the Windows Remote Access Connection Manager (RasMan) service, through coordinated disclosure. Microsoft later credited the researchers for the finding.
8 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.