CyberzSOC

Publication detail
← Back to advisories & guidance

Microsoft Releases February 2026 Security Updates ↗ source

February 12, 2026 JPCERT/CC Alert

Summary

Attackers leveraging these vulnerabilities may be able to gain SYSTEM privileges, among other impacts. February 2026 Security Updates According to Microsoft, among the vulnerabilities, the following vulnerability has been confirmed to be exploited in the wild. Please consider applying the security update programs by referring to the information provided by Microsoft. Windows Shell Security Feature Bypass Vulnerability MSHTML Framework Security Feature Bypass Vulnerability Microsoft Word Security Feature Bypass Vulnerability Desktop Window Manager Elevation of Privilege Vulnerability Windows Remote Access Connection Manager Denial of Service Vulnerability Windows Remote Desktop Services Elevation of Privilege Vulnerability Please apply the security update programs through Microsoft Update, Windows Update, etc. If you have any information regarding this alert, please contact JPCERT/CC.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2026-21510 8.8 High Microsoft Windows Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature …
CVE-2026-21513 8.8 High Microsoft Windows Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security featu…
CVE-2026-21514 7.8 High Microsoft Office Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate…
CVE-2026-21519 7.8 High Microsoft Windows Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.
CVE-2026-21533 7.8 High Microsoft Windows Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate …
CVE-2026-21525 6.2 Medium Microsoft Windows Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service loca…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.