Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Microsoft Patch Tuesday: 6 exploited zero-days fixed in February 2026
    Cybersecurity

    Microsoft Patch Tuesday: 6 exploited zero-days fixed in February 2026

    adminBy adminFebruary 11, 2026No Comments4 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Microsoft Patch Tuesday: 6 exploited zero-days fixed in February 2026
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Microsoft has plugged 50+ security holes on February 2026 Patch Tuesday, including six zero-day vulnerabilities exploited by attackers in the wild.

    The “security feature bypass” zero-days

    Among the zero-days fixed are three vulnerabilities that allow attackers to bypass a security feature.

    CVE-2026-21513 affects the MSHTML/Trident browser engine for the Microsoft Windows version of Internet Explorer, and CVE-2026-21514 affects Microsoft Word.

    The former can be exploited by attackers by convincing a user to open a malicious HTML or shortcut (.lnk) file that has been crafted to manipulate browser and Windows Shell handling.

    The latter can be triggered by a malicious Office file crafted to bypass OLE mitigations in Microsoft 365 and Microsoft Office. (If this sounds familiar, it’s because Microsoft recently fixed a similar flaw with an emergency update due to in-the-wild attacks.)

    CVE-2026-21510 is the third security feature bypass zero-day fixed this time around. It affects Windows Shell, can be exploited with a malicious link or shortcut file, allowing attackers to bypass Windows SmartScreen and Windows Shell security prompts and execute files “without user warning or consent.”

    All three flaws were publicly known and reported by Google Threat Intelligence Group, Microsoft Threat Intelligence Center (MSTIC), Microsoft Security Response Center (MSRC), and the Office Product Group Security Team, along with an anonymous researcher.

    Patching publicly known vulnerabilities should be a priority, especially if, like these, are actively exploited by attackers.

    The three remaining zero-days

    CVE-2026-21519 is a Desktop Window Manager vulnerability that allows attackers to elevate their privileges to SYSTEM on an already compromised host. It was reported by MSTIC and MSRC.

    CVE-2026-21525 is a vulnerability in Windows Remote Access Connection Manager (“RasMan”) that may allow an unprivileged user to crash the service. It was reported by the 0patch research team, who discovered an exploit for it in a public malware repository.

    CVE-2026-21533 is an elevation of privilege flaw affecting Windows Remote Desktop Services. It was reported by Crowdstrike researchers.

    “The CVE-2026-21533 exploit binary modifies a service configuration key, replacing it with an attacker-controlled key, which could enable adversaries to escalate privileges to add a new user to the Administrator group. CrowdStrike Intelligence retrospective hunting has revealed that threat actors had used this binary in the wild to target U.S. and Canada-based entities since at least December 24, 2025,” the cybersecurity company noted.

    “CrowdStrike Intelligence assesses that Microsoft’s public disclosure of CVE-2026-21533 will almost certainly encourage threat actors possessing CVE-2026-21533 exploit binaries, as well as any exploit brokers possessing the underlying exploit, to use or monetize the exploits in the near term.”

    Ryan Braunstein, Security Manager at Automox, also pointed out that the RasMan DoS flaw (CVE-2026-21525) should be patched quickly, as it could lead to widespread problems, since the service is responsible for maintaining VPN connections to corporate networks.

    “An attacker with a foothold as a standard, non-admin user can run a small script that crashes the RAS manager service. The attack requires no elevated privileges and can be triggered after initial access through phishing or a malicious browser extension,” he explained.

    “Organizations relying on always-on VPN connections face a particular risk: if the VPN service crashes, endpoints configured with “fail close” policies lose network access entirely. IT teams can’t reach those machines to patch them or run automation. In larger environments, this creates cascading failures that can take hours to resolve.”

    Such a widespread crash could be used a distraction while executing a separate attack against servers or exfiltrating data, he added. “If you run servers with RRAS (Routing and Remote Access Service), include them in your priority patching list to protect automations and infrastructure.”

    Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

    Exploited February fixed Microsoft Patch Tuesday ZeroDays
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleAndroid widgets are a lie (and my home screen proves it)
    Next Article Nvidia’s AI upscaling works on games it wasn’t designed for, and the results are wild
    admin
    • Website

    Related Posts

    Microsoft Web IQ Gives AI Agents Bing Grounding APIs

    June 2, 2026

    FTC broadens Microsoft probe to cloud, AI, and software bundling

    June 2, 2026

    Microsoft Clarity Now Shows Grounding Queries Behind AI Citations

    May 22, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    How Google Display exclusions guide AI-driven optimization

    June 4, 2026

    How to show in search, social, and AI

    June 4, 2026

    9 Best Cheap Cell Phone Plans That Will Save You Money

    June 4, 2026

    How To Fix Google Ads Smart Bidding With A Primary vs. Secondary Conversion Framework

    June 4, 2026
    Categories
    • Blogging (89)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (234)
    • SEO & Digital Marketing (1,364)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (330)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    How Google Display exclusions guide AI-driven optimization

    June 4, 2026

    How to show in search, social, and AI

    June 4, 2026

    9 Best Cheap Cell Phone Plans That Will Save You Money

    June 4, 2026
    Most Popular
    • How Google Display exclusions guide AI-driven optimization
    • How to show in search, social, and AI
    • 9 Best Cheap Cell Phone Plans That Will Save You Money
    • How To Fix Google Ads Smart Bidding With A Primary vs. Secondary Conversion Framework
    • What is Cisco Cloud Control and why should customers care?
    • From keyword manager to system optimizer
    • 11 Ways to Lower Your Cell Phone Bill
    • Google Search Console adds AI performance reports and blocking controls
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.