In the recent February 2026 security update, Microsoft had to face a particularly critical situation. The company released patches to fix six zero-day vulnerabilities already actively exploited by malicious actors, along with dozens of other security issues in its most widely used products.
On February 10, 2026, during the usual “Patch Tuesday,” Microsoft released security updates to fix between 58 and 60 vulnerabilities affecting Windows, Office, Azure, Edge, and other company products. What makes this update cycle particularly concerning is the presence of six zero-day vulnerabilities, or security flaws already known and exploited by attackers before fixes were available. Three of these vulnerabilities had been publicly disclosed before the patches were released. The most serious vulnerabilities include issues in Windows SmartScreen (CVE-2026-21510) and Internet Explorer/MSHTML (CVE-2026-21513), both with a CVSS severity score of 8.8 out of 10, which allow bypassing protection mechanisms. Other critical issues affect Microsoft Word, Desktop Window Manager, Remote Desktop, and the Windows Remote Access Connection Manager.
These types of vulnerabilities represent a significant risk for companies and users, as attacks are already underway. Attackers can exploit these flaws to gain unauthorized access to systems, elevate their privileges, execute malicious code, or cause service disruptions. The United States Cybersecurity and Infrastructure Security Agency (CISA) took the situation so seriously that it added all six vulnerabilities to its catalog of known exploited vulnerabilities.
To protect against these risks, companies and users should immediately apply the security updates released by Microsoft. It is advisable to enable automatic updates on Windows devices and regularly verify that systems are up to date. Organizations should also implement an efficient patch management process, prioritize vulnerabilities classified as “actively exploited,” and monitor their systems to detect any signs of compromise.
- Key points to remember:
- Microsoft has fixed six zero-day vulnerabilities already actively exploited, along with dozens of other security flaws in its most widely used products
- The vulnerabilities affect critical components such as Windows SmartScreen, MSHTML, Microsoft Word, and Remote Desktop, with potentially serious security consequences
- It is essential to immediately apply the security updates released by Microsoft to protect your systems
Sources:
cyberscoop.com/microsoft-patch-tuesday-february-2026/
securityaffairs.com/187848/uncategorized/microsoft-patch-tuesday-security-updates-for-february-2026-fix-six-actively-exploited-zero-days.html
computerweekly.com/news/366638958/February-Patch-Tuesday-Microsoft-drops-six-zero-days
securityweek.com/6-actively-exploited-zero-days-patched-by-microsoft-with-february-2026-updates/
Source: CSIRT Italia