Microsoft released its February 2026 Patch Tuesday yesterday , fixing a total of 58 vulnerabilities in the Windows ecosystem and its applications. This is one of the most significant updates in recent months, as it includes six zero-day vulnerabilities , that is, bugs that have already been actively exploited by attackers (while three of them were made public before there was an official fix).

This release comes at a time when cyberattacks are on the rise, with ransomware groups and state-backed actors exploiting every available security hole in corporate and personal systems.
Five “Critical” vulnerabilities and dozens of fixes
Microsoft rated five of the vulnerabilities as "Critical", with three related to elevation of privilege and two to disclosure of sensitive information.
See also: Fortinet fixes critical vulnerability that allows code execution
In detail, the corrections are distributed as follows:
- 25 vulnerabilities that allow elevation of privilege
- 12 vulnerabilities that allow remote code execution
- 7 vulnerabilities that allow spoofing
- 6 vulnerabilities that allow information disclosure
- 5 vulnerabilities that allow security features to be bypassed
- 3 vulnerabilities that allow Denial of Service attacks
It is worth noting that three Microsoft Edge vulnerabilities that were patched earlier in the month are not included.
New Secure Boot certificates: End of an era for 2011 keys
Along with the security updates, Microsoft has also begun the gradual replacement of Secure Boot , which expire at the end of June 2026.
According to Windows 11 notes, devices will only receive the new certificates when the system shows sufficient signals of successful update, so that the transition can be done in a safe and controlled manner.
This move is considered critical, as Secure Boot is a key defense mechanism against bootkits and rootkits that attempt to infect the system before the operating system even starts.
See also: BeyondTrust patches critical RCE vulnerability in Remote Support and PRA

February Patch Tuesday: Six zero-day vulnerabilities
The bulk of the update falls on six zero-day vulnerabilities that have already been exploited in real attacks. Microsoft considers a zero-day to be any vulnerability that is either actively exploited or has been publicly disclosed before an official patch is available.
CVE-2026-21510: Windows Shell Security Feature Bypass Vulnerability
This vulnerability allows attackers to bypass Windows SmartScreen security prompts by simply convincing the user to open a malicious link or shortcut file.
"An attacker could bypass Windows SmartScreen and Windows Shell security prompts by exploiting improper handling of Windows Shell components and allowing content to run attacker-controlled," Microsoft continued.
It is likely related to Mark of the Web (MoTW), which have become a key target of phishing campaigns.
CVE-2026-21513: MSHTML Framework Security Feature Bypass Vulnerability
Another serious vulnerability has been identified in the MSHTML Framework, allowing security bypass . Although technical details have not been provided, the fact that it is actively exploited indicates that it is a tool for targeted attacks.
CVE-2026-21514: Microsoft Word Security Feature Bypass Vulnerability
Microsoft also patched a vulnerability in Word that bypasses OLE mitigations in Microsoft 365 and Office. An attacker would need to send a malicious document and convince the user to open it, which remains a classic social engineering tactic.
Microsoft says the flaw cannot be exploited in the Office Preview Pane.
CVE-2026-21519: Desktop Window Manager Elevation of Privilege Vulnerability
This bug allows an attacker to gain SYSTEM privileges, the highest level of access to Windows. It is located in the Desktop Window Manager. Such vulnerabilities are often used after an initial infection to gain complete control of the system.
See also: SmarterMail fixes critical RCE vulnerability
CVE-2026-21525: Windows Remote Access Connection Manager DOS Vulnerability
Microsoft has patched an actively exploited denial of service flaw in Remote Access Connection Manager. The ACROS team and 0patch had identified the exploit as early as December 2025 in a public malware repository, suggesting professional development of attack tools.

CVE-2026-21533: Windows Remote Desktop Services Elevation of Privilege Vulnerability
This vulnerability involves elevation of privilege in Windows Remote Desktop Services.
CrowdStrike has uncovered an exploit that allows threat actors to modify service settings and add a new user to the administrators group. Experts believe that this vulnerability could soon be sold or exploited on a mass scale.
Microsoft Patch Tuesday February 2026: All vulnerabilities
In the table below, you can see all the vulnerabilities being fixed this month:
| Tags | CVE ID | CVE Title | Severity |
|---|---|---|---|
| .NET | CVE-2026-21218 | .NET Spoofing Vulnerability | Important |
| Azure Arc | CVE-2026-24302 | Azure Arc Elevation of Privilege Vulnerability | Critical |
| Azure Compute Gallery | CVE-2026-23655 | Microsoft ACI Confidential Containers Information Disclosure Vulnerability | Critical |
| Azure Compute Gallery | CVE-2026-21522 | Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability | Critical |
| Azure DevOps Server | CVE-2026-21512 | Azure DevOps Server Cross-Site Scripting Vulnerability | Important |
| Azure Front Door (AFD) | CVE-2026-24300 | Azure Front Door Elevation of Privilege Vulnerability | Critical |
| Azure Functions | CVE-2026-21532 | Azure Function Information Disclosure Vulnerability | Critical |
| Azure HDInsights | CVE-2026-21529 | Azure HDInsight Spoofing Vulnerability | Important |
| Azure IoT SDK | CVE-2026-21528 | Azure IoT Explorer Information Disclosure Vulnerability | Important |
| Azure Local | CVE-2026-21228 | Azure Local Remote Code Execution Vulnerability | Important |
| Azure SDK | CVE-2026-21531 | Azure SDK for Python Remote Code Execution Vulnerability | Important |
| Desktop Window Manager | CVE-2026-21519 | Desktop Window Manager Elevation of Privilege Vulnerability | Important |
| Github Copilot | CVE-2026-21516 | GitHub Copilot for Jetbrains Remote Code Execution Vulnerability | Important |
| GitHub Copilot and Visual Studio | CVE-2026-21523 | GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability | Important |
| GitHub Copilot and Visual Studio | CVE-2026-21256 | GitHub Copilot and Visual Studio Remote Code Execution Vulnerability | Important |
| GitHub Copilot and Visual Studio | CVE-2026-21257 | GitHub Copilot and Visual Studio Elevation of Privilege Vulnerability | Important |
| GitHub Copilot and Visual Studio Code | CVE-2026-21518 | GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability | Important |
| Mailslot File System | CVE-2026-21253 | Mailslot File System Elevation of Privilege Vulnerability | Important |
| Microsoft Defender for Linux | CVE-2026-21537 | Microsoft Defender for Endpoint Linux Extension Remote Code Execution Vulnerability | Important |
| Microsoft Edge (Chromium-based) | CVE-2026-1861 | Chromium: CVE-2026-1861 Heap buffer overflow in libvpx | Unknown |
| Microsoft Edge (Chromium-based) | CVE-2026-1862 | Chromium: CVE-2026-1862 Type Confusion in V8 | Unknown |
| Microsoft Edge for Android | CVE-2026-0391 | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability | Moderate |
| Microsoft Exchange Server | CVE-2026-21527 | Microsoft Exchange Server Spoofing Vulnerability | Important |
| Microsoft Graphics Component | CVE-2026-21246 | Windows Graphics Component Elevation of Privilege Vulnerability | Important |
| Microsoft Graphics Component | CVE-2026-21235 | Windows Graphics Component Elevation of Privilege Vulnerability | Important |
| Microsoft Office Excel | CVE-2026-21261 | Microsoft Excel Information Disclosure Vulnerability | Important |
| Microsoft Office Excel | CVE-2026-21258 | Microsoft Excel Information Disclosure Vulnerability | Important |
| Microsoft Office Excel | CVE-2026-21259 | Microsoft Excel Elevation of Privilege Vulnerability | Important |
| Microsoft Office Outlook | CVE-2026-21260 | Microsoft Outlook Spoofing Vulnerability | Important |
| Microsoft Office Outlook | CVE-2026-21511 | Microsoft Outlook Spoofing Vulnerability | Important |
| Microsoft Office Word | CVE-2026-21514 | Microsoft Word Security Feature Bypass Vulnerability | Important |
| MSHTML Framework | CVE-2026-21513 | MSHTML Framework Security Feature Bypass Vulnerability | Important |
| Power BI | CVE-2026-21229 | Power BI Remote Code Execution Vulnerability | Important |
| Role: Windows Hyper-V | CVE-2026-21244 | Windows Hyper-V Remote Code Execution Vulnerability | Important |
| Role: Windows Hyper-V | CVE-2026-21255 | Windows Hyper-V Security Feature Bypass Vulnerability | Important |
| Role: Windows Hyper-V | CVE-2026-21248 | Windows Hyper-V Remote Code Execution Vulnerability | Important |
| Role: Windows Hyper-V | CVE-2026-21247 | Windows Hyper-V Remote Code Execution Vulnerability | Important |
| Windows Ancillary Function Driver for WinSock | CVE-2026-21236 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important |
| Windows Ancillary Function Driver for WinSock | CVE-2026-21241 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important |
| Windows Ancillary Function Driver for WinSock | CVE-2026-21238 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important |
| Windows App for Mac | CVE-2026-21517 | Windows App for Mac Installer Elevation of Privilege Vulnerability | Important |
| Windows Cluster Client Failover | CVE-2026-21251 | Cluster Client Failover (CCF) Elevation of Privilege Vulnerability | Important |
| Windows Connected Devices Platform Service | CVE-2026-21234 | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | Important |
| Windows GDI+ | CVE-2026-20846 | GDI+ Denial of Service Vulnerability | Important |
| Windows HTTP.sys | CVE-2026-21240 | Windows HTTP.sys Elevation of Privilege Vulnerability | Important |
| Windows HTTP.sys | CVE-2026-21250 | Windows HTTP.sys Elevation of Privilege Vulnerability | Important |
| Windows HTTP.sys | CVE-2026-21232 | Windows HTTP.sys Elevation of Privilege Vulnerability | Important |
| Windows Kernel | CVE-2026-21231 | Windows Kernel Elevation of Privilege Vulnerability | Important |
| Windows Kernel | CVE-2026-21222 | Windows Kernel Information Disclosure Vulnerability | Important |
| Windows Kernel | CVE-2026-21239 | Windows Kernel Elevation of Privilege Vulnerability | Important |
| Windows Kernel | CVE-2026-21245 | Windows Kernel Elevation of Privilege Vulnerability | Important |
| Windows LDAP – Lightweight Directory Access Protocol | CVE-2026-21243 | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | Important |
| Windows Notepad App | CVE-2026-20841 | Windows Notepad App Remote Code Execution Vulnerability | Important |
| Windows NTLM | CVE-2026-21249 | Windows NTLM Spoofing Vulnerability | Important |
| Windows Remote Access Connection Manager | CVE-2026-21525 | Windows Remote Access Connection Manager Denial of Service Vulnerability | Moderate |
| Windows Remote Desktop | CVE-2026-21533 | Windows Remote Desktop Services Elevation of Privilege Vulnerability | Important |
| Windows Shell | CVE-2026-21510 | Windows Shell Security Feature Bypass Vulnerability | Important |
| Windows Storage | CVE-2026-21508 | Windows Storage Elevation of Privilege Vulnerability | Important |
| Windows Subsystem for Linux | CVE-2026-21237 | Windows Subsystem for Linux Elevation of Privilege Vulnerability | Important |
| Windows Subsystem for Linux | CVE-2026-21242 | Windows Subsystem for Linux Elevation of Privilege Vulnerability | Important |
| Windows Win32K – GRFX | CVE-2023-2804 | Red Hat, Inc. CVE-2023-2804: Heap Based Overflow libjpeg-turbo | Important |
Source: www.bleepingcomputer.com
