By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: February Patch Tuesday: Microsoft drops six zero-days | Computer Weekly
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > February Patch Tuesday: Microsoft drops six zero-days | Computer Weekly
News

February Patch Tuesday: Microsoft drops six zero-days | Computer Weekly

News Room
Last updated: 2026/02/10 at 8:06 PM
News Room Published 10 February 2026
Share
February Patch Tuesday: Microsoft drops six zero-days | Computer Weekly
SHARE

Microsoft has released fixes for six newly-classified zero-day common vulnerabilities and exposures (CVEs) on the second monthly Patch Tuesday of 2026, amid a release comprising over 50 flaws that run the full gamut of Microsoft’s product suite.

Although the total number of flaws is down by about half on January’s bumper crop, it is about on par for this time of year, explained Dustin Childs of Trend Micro’s Zero Day Initiative (ZDI), however, he added, the number under active attack is “extraordinarily high”.

Indeed, with all six zero-days under active exploitation in the wild, and three of them already made public, Childs noted: “We’ll see if we’re on our way to another ‘hot exploit summer’ as we saw a few years ago or if this is just an aberration.”

The three ‘classic’ zero-days are all security feature bypass (SFB) vulnerabilities, tracked variously as CVE-2026-21510 in Windows SmartScreen, CVE-2026-21514 in Microsoft Word, and CVE-2026-21513 in Internet Explorer.

The three zero-days for which exploit proofs of concept (PoCs) have not yet been made public are tracked as CVE-2026-21519, an elevation of privilege (EoP) flaw in Desktop Window Manager, CVE-2026-21525, a denial of service (DoS) flaw in Windows Remote Access Connection Manager, and finally, CVE-2026-21533, an EoP flaw in Windows Remote Desktop Services.

Seth Hoyt, senior security engineer at endpoint security platform Automox, said the flaw in Windows Shell was particularly dangerous because its effect is essentially to neutralise the important SmartScreen feature in Microsoft Defender.

“SmartScreen serves as a critical checkpoint: when you download an executable or document, it prompts you to confirm whether you trust the source. This bypass removes that checkpoint entirely,” he said. “Files from the internet execute without triggering the usual warning dialog, giving attackers a clean path to run malicious code once a user clicks a phishing link.

“The attack still requires user interaction, but with one less security prompt in the way, the barrier to successful exploitation drops considerably,” said Hoyt.

Beyond patching, he advised defenders to be alert to unusual cmd.exe or PowerShell activity in the wake of a file download, or odd processes spawning from files in Downloads or temporary directories that do not have corresponding SmartScreen events logged. It is also worth applying endpoint hardening measures such as Attack Surface Reduction rules.

Hoyt added that CVE-2026-21514 works in a similar fashion and should be treated in the same terms.

Meanwhile, Jack Bicer, vulnerability research director at patch management specialist Action1, turned to the MSHTML Framework flaw in Internet Explorer, CVE-2026-21513.

“The MSHTML Framework [is] a core component used by Windows and multiple applications to render HTML content,” he said. “[CVE-2026-21513] is caused by a protection mechanism failure that allows attackers to bypass execution prompts when users interact with malicious files. A crafted file can silently bypass Windows security prompts and trigger dangerous actions with a single click.

“Exploitation occurs over the network and requires user interaction, such as opening a malicious HTML file or clicking a shortcut delivered via email, link, or download. No privileges are required by the attacker,” he added.

Bicer explained that such SFB flaws significantly increase the success rate of phishing and campaigns that ultimately have impacts far beyond embarrassment for the one person who accidentally clicked on something without thinking. In enterprise environments they become a gateway to a whole host of nasties, including unauthorised code execution, malware and ransomware deployment, credential and data theft, and other compromises.

Deep dependence

Coming a month after January’s blockbuster Patch Tuesday, Cory Simpson, senior advisor to the Cyberspace Solarium Commission and a former advisor to the US Special Operations Command, said that 2026 was already off to a concerning start.

He described the situation on the ground as standing in “stark contrast” to the picture painted in Microsoft’s November 2025 Secure Future Initiative report, which hailed the idea of ‘security above all else’ as a guiding principle at Redmond.

“Patch volumes like today’s, six active zero-days, reflect the structural risk created by deep dependence on Microsoft across enterprise environments,” Simpson told Computer Weekly.

“Security leadership starts with baseline hygiene and extends to resilience-by-design: diversified dependencies, reduced concentration risk, and architectures built to operate under persistent vulnerability discovery,” he said.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Ecovacs' Latest Robot Lawn Mowers Can Run Wire-Free Ecovacs' Latest Robot Lawn Mowers Can Run Wire-Free
Next Article The best TV shows of 2025, according to social media The best TV shows of 2025, according to social media
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

USSD at Scale: Powering Healthcare Access Across Africa | HackerNoon
USSD at Scale: Powering Healthcare Access Across Africa | HackerNoon
Computing
You Can See How Much Money You’ve Spent On Steam (If You’re Brave Enough) – BGR
You Can See How Much Money You’ve Spent On Steam (If You’re Brave Enough) – BGR
News
There is a lack of humans to build AI data centers
There is a lack of humans to build AI data centers
Mobile
AI infrastructure giant Nebius buys agentic search startup Tavily –  News
AI infrastructure giant Nebius buys agentic search startup Tavily – News
News

You Might also Like

You Can See How Much Money You’ve Spent On Steam (If You’re Brave Enough) – BGR
News

You Can See How Much Money You’ve Spent On Steam (If You’re Brave Enough) – BGR

4 Min Read
AI infrastructure giant Nebius buys agentic search startup Tavily –  News
News

AI infrastructure giant Nebius buys agentic search startup Tavily – News

6 Min Read
Samsung is finally considering custom font support for Samsung Notes
News

Samsung is finally considering custom font support for Samsung Notes

4 Min Read
Bezos could have saved WaPo’s sports and local journalists. He laid them off instead.
News

Bezos could have saved WaPo’s sports and local journalists. He laid them off instead.

19 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?