HomeUpdatesMicrosoft Patch Tuesday February 2026: Fixes for 58 vulnerabilities

Microsoft Patch Tuesday February 2026: Fixes for 58 vulnerabilities

Microsoft released its February 2026 Patch Tuesday yesterday , fixing a total of 58 vulnerabilities in the Windows ecosystem and its applications. This is one of the most significant updates in recent months, as it includes six zero-day vulnerabilities , that is, bugs that have already been actively exploited by attackers (while three of them were made public before there was an official fix).

Microsoft Patch Tuesday February 2026 vulnerabilities

This release comes at a time when cyberattacks are on the rise, with ransomware groups and state-backed actors exploiting every available security hole in corporate and personal systems.

Five “Critical” vulnerabilities and dozens of fixes

Microsoft rated five of the vulnerabilities as "Critical", with three related to elevation of privilege and two to disclosure of sensitive information.

See also: Fortinet fixes critical vulnerability that allows code execution

In detail, the corrections are distributed as follows:

  • 25 vulnerabilities that allow elevation of privilege
  • 12 vulnerabilities that allow remote code execution
  • 7 vulnerabilities that allow spoofing
  • 6 vulnerabilities that allow information disclosure
  • 5 vulnerabilities that allow security features to be bypassed
  • 3 vulnerabilities that allow Denial of Service attacks

It is worth noting that three Microsoft Edge vulnerabilities that were patched earlier in the month are not included.

New Secure Boot certificates: End of an era for 2011 keys

Along with the security updates, Microsoft has also begun the gradual replacement of Secure Boot , which expire at the end of June 2026.

According to Windows 11 notes, devices will only receive the new certificates when the system shows sufficient signals of successful update, so that the transition can be done in a safe and controlled manner.

This move is considered critical, as Secure Boot is a key defense mechanism against bootkits and rootkits that attempt to infect the system before the operating system even starts.

See also: BeyondTrust patches critical RCE vulnerability in Remote Support and PRA

Microsoft Patch Tuesday February 2026: Fixes for 58 vulnerabilities

February Patch Tuesday: Six zero-day vulnerabilities

The bulk of the update falls on six zero-day vulnerabilities that have already been exploited in real attacks. Microsoft considers a zero-day to be any vulnerability that is either actively exploited or has been publicly disclosed before an official patch is available.

CVE-2026-21510: Windows Shell Security Feature Bypass Vulnerability

This vulnerability allows attackers to bypass Windows SmartScreen security prompts by simply convincing the user to open a malicious link or shortcut file.

"An attacker could bypass Windows SmartScreen and Windows Shell security prompts by exploiting improper handling of Windows Shell components and allowing content to run attacker-controlled," Microsoft continued.

It is likely related to Mark of the Web (MoTW), which have become a key target of phishing campaigns.

CVE-2026-21513: MSHTML Framework Security Feature Bypass Vulnerability

Another serious vulnerability has been identified in the MSHTML Framework, allowing security bypass . Although technical details have not been provided, the fact that it is actively exploited indicates that it is a tool for targeted attacks.

CVE-2026-21514: Microsoft Word Security Feature Bypass Vulnerability

Microsoft also patched a vulnerability in Word that bypasses OLE mitigations in Microsoft 365 and Office. An attacker would need to send a malicious document and convince the user to open it, which remains a classic social engineering tactic.

Microsoft says the flaw cannot be exploited in the Office Preview Pane.

CVE-2026-21519: Desktop Window Manager Elevation of Privilege Vulnerability

This bug allows an attacker to gain SYSTEM privileges, the highest level of access to Windows. It is located in the Desktop Window Manager. Such vulnerabilities are often used after an initial infection to gain complete control of the system.

See also: SmarterMail fixes critical RCE vulnerability

CVE-2026-21525: Windows Remote Access Connection Manager DOS Vulnerability

Microsoft has patched an actively exploited denial of service flaw in Remote Access Connection Manager. The ACROS team and 0patch had identified the exploit as early as December 2025 in a public malware repository, suggesting professional development of attack tools.

Microsoft Patch Tuesday February 2026: Fixes for 58 vulnerabilities

CVE-2026-21533: Windows Remote Desktop Services Elevation of Privilege Vulnerability

This vulnerability involves elevation of privilege in Windows Remote Desktop Services.

CrowdStrike has uncovered an exploit that allows threat actors to modify service settings and add a new user to the administrators group. Experts believe that this vulnerability could soon be sold or exploited on a mass scale.

Microsoft Patch Tuesday February 2026: All vulnerabilities

In the table below, you can see all the vulnerabilities being fixed this month:

TagsCVE IDCVE TitleSeverity
.NETCVE-2026-21218.NET Spoofing VulnerabilityImportant
Azure ArcCVE-2026-24302Azure Arc Elevation of Privilege VulnerabilityCritical
Azure Compute GalleryCVE-2026-23655Microsoft ACI Confidential Containers Information Disclosure VulnerabilityCritical
Azure Compute GalleryCVE-2026-21522Microsoft ACI Confidential Containers Elevation of Privilege VulnerabilityCritical
Azure DevOps ServerCVE-2026-21512Azure DevOps Server Cross-Site Scripting VulnerabilityImportant
Azure Front Door (AFD)CVE-2026-24300Azure Front Door Elevation of Privilege VulnerabilityCritical
Azure FunctionsCVE-2026-21532Azure Function Information Disclosure VulnerabilityCritical
Azure HDInsightsCVE-2026-21529Azure HDInsight Spoofing VulnerabilityImportant
Azure IoT SDKCVE-2026-21528Azure IoT Explorer Information Disclosure VulnerabilityImportant
Azure LocalCVE-2026-21228Azure Local Remote Code Execution VulnerabilityImportant
Azure SDKCVE-2026-21531Azure SDK for Python Remote Code Execution VulnerabilityImportant
Desktop Window ManagerCVE-2026-21519Desktop Window Manager Elevation of Privilege VulnerabilityImportant
Github CopilotCVE-2026-21516GitHub Copilot for Jetbrains Remote Code Execution VulnerabilityImportant
GitHub Copilot and Visual StudioCVE-2026-21523GitHub Copilot and Visual Studio Code Remote Code Execution VulnerabilityImportant
GitHub Copilot and Visual StudioCVE-2026-21256GitHub Copilot and Visual Studio Remote Code Execution VulnerabilityImportant
GitHub Copilot and Visual StudioCVE-2026-21257GitHub Copilot and Visual Studio Elevation of Privilege VulnerabilityImportant
GitHub Copilot and Visual Studio CodeCVE-2026-21518GitHub Copilot and Visual Studio Code Security Feature Bypass VulnerabilityImportant
Mailslot File SystemCVE-2026-21253Mailslot File System Elevation of Privilege VulnerabilityImportant
Microsoft Defender for LinuxCVE-2026-21537Microsoft Defender for Endpoint Linux Extension Remote Code Execution VulnerabilityImportant
Microsoft Edge (Chromium-based)CVE-2026-1861Chromium: CVE-2026-1861 Heap buffer overflow in libvpxUnknown
Microsoft Edge (Chromium-based)CVE-2026-1862Chromium: CVE-2026-1862 Type Confusion in V8Unknown
Microsoft Edge for AndroidCVE-2026-0391Microsoft Edge (Chromium-based) for Android Spoofing VulnerabilityModerate
Microsoft Exchange ServerCVE-2026-21527Microsoft Exchange Server Spoofing VulnerabilityImportant
Microsoft Graphics ComponentCVE-2026-21246Windows Graphics Component Elevation of Privilege VulnerabilityImportant
Microsoft Graphics ComponentCVE-2026-21235Windows Graphics Component Elevation of Privilege VulnerabilityImportant
Microsoft Office ExcelCVE-2026-21261Microsoft Excel Information Disclosure VulnerabilityImportant
Microsoft Office ExcelCVE-2026-21258Microsoft Excel Information Disclosure VulnerabilityImportant
Microsoft Office ExcelCVE-2026-21259Microsoft Excel Elevation of Privilege VulnerabilityImportant
Microsoft Office OutlookCVE-2026-21260Microsoft Outlook Spoofing VulnerabilityImportant
Microsoft Office OutlookCVE-2026-21511Microsoft Outlook Spoofing VulnerabilityImportant
Microsoft Office WordCVE-2026-21514Microsoft Word Security Feature Bypass VulnerabilityImportant
MSHTML FrameworkCVE-2026-21513MSHTML Framework Security Feature Bypass VulnerabilityImportant
Power BICVE-2026-21229Power BI Remote Code Execution VulnerabilityImportant
Role: Windows Hyper-VCVE-2026-21244Windows Hyper-V Remote Code Execution VulnerabilityImportant
Role: Windows Hyper-VCVE-2026-21255Windows Hyper-V Security Feature Bypass VulnerabilityImportant
Role: Windows Hyper-VCVE-2026-21248Windows Hyper-V Remote Code Execution VulnerabilityImportant
Role: Windows Hyper-VCVE-2026-21247Windows Hyper-V Remote Code Execution VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2026-21236Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2026-21241Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2026-21238Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows App for MacCVE-2026-21517Windows App for Mac Installer Elevation of Privilege VulnerabilityImportant
Windows Cluster Client FailoverCVE-2026-21251Cluster Client Failover (CCF) Elevation of Privilege VulnerabilityImportant
Windows Connected Devices Platform ServiceCVE-2026-21234Windows Connected Devices Platform Service Elevation of Privilege VulnerabilityImportant
Windows GDI+CVE-2026-20846GDI+ Denial of Service VulnerabilityImportant
Windows HTTP.sysCVE-2026-21240Windows HTTP.sys Elevation of Privilege VulnerabilityImportant
Windows HTTP.sysCVE-2026-21250Windows HTTP.sys Elevation of Privilege VulnerabilityImportant
Windows HTTP.sysCVE-2026-21232Windows HTTP.sys Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2026-21231Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2026-21222Windows Kernel Information Disclosure VulnerabilityImportant
Windows KernelCVE-2026-21239Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2026-21245Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows LDAP – Lightweight Directory Access ProtocolCVE-2026-21243Windows Lightweight Directory Access Protocol (LDAP) Denial of Service VulnerabilityImportant
Windows Notepad AppCVE-2026-20841Windows Notepad App Remote Code Execution VulnerabilityImportant
Windows NTLMCVE-2026-21249Windows NTLM Spoofing VulnerabilityImportant
Windows Remote Access Connection ManagerCVE-2026-21525Windows Remote Access Connection Manager Denial of Service VulnerabilityModerate
Windows Remote DesktopCVE-2026-21533Windows Remote Desktop Services Elevation of Privilege VulnerabilityImportant
Windows ShellCVE-2026-21510Windows Shell Security Feature Bypass VulnerabilityImportant
Windows StorageCVE-2026-21508Windows Storage Elevation of Privilege VulnerabilityImportant
Windows Subsystem for LinuxCVE-2026-21237Windows Subsystem for Linux Elevation of Privilege VulnerabilityImportant
Windows Subsystem for LinuxCVE-2026-21242Windows Subsystem for Linux Elevation of Privilege VulnerabilityImportant
Windows Win32K – GRFXCVE-2023-2804Red Hat, Inc. CVE-2023-2804: Heap Based Overflow libjpeg-turboImportant

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS