What better way to say I love you than with an update? Attackers exploited a whopping six Microsoft bugs as zero-days prior to Redmond releasing software fixes on February's Patch Tuesday. For comparison, last month we saw just one Windows vulnerability under attack before the January Patch Tuesday fix. Of course, then there's also the emergency patches released because the first try didn't plug the security hole - but that's a different story. As always, Microsoft did not provide any additional details about who attacked these six flaws and how widespread exploitation may be. But considering that three of the six are also listed as publicly disclosed - meaning there may already be proof-of-concept exploits floating around the internet - we expect to see more reports (and details) about active exploitation soon. Here's what we do know about the six CVEs under attack, and you can read about all 59 Microsoft CVEs here. Windows Shell Security Feature Bypass Vulnerability (CVE-2026-21510): Exploiting this bug, which received an 8.8 CVSS rating, requires an attacker to convince a user to open a malicious link or shortcut file - but we all know that most people will click on just about anything, so that's not difficult to pull off. Once the user opens the malicious link, the attacker can bypass Windows SmartScreen and Windows Shell security prompts to execute code on the victim's system without user warning or consent. As Trend Micro Zero Day Initiative's Dustin Childs warns, "this...
Microsoft's Valentine's gift to admins: 6 exploited zero-day fixes
The Register
·Jessica Lyons
·Published Feb 10, 2026
·Updated
Affected Software
6 affected components
Microsoft Windows Shell=CVE-2026-21510
Microsoft Internet Explorer=CVE-2026-21513
Microsoft Microsoft Word=CVE-2026-21514
Microsoft Desktop Window Manager=CVE-2026-21519
Microsoft Windows Remote Access Connection Manager=CVE-2026-21525
Microsoft Windows Remote Desktop Services=CVE-2026-21533
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the release of critical security updates by Microsoft to address six exploited zero-day vulnerabilities.
2
What security implications are discussed in the article?
The article highlights the risks associated with six zero-day exploits that attackers were actively using prior to the patch release.
3
What products or software are affected by the vulnerabilities?
The affected products include Microsoft Windows Shell, Internet Explorer, Microsoft Word, Desktop Window Manager, Windows Remote Access Connection Manager, and Windows Remote Desktop Services.
4
What is the significance of the timing of these updates?
The updates were released in February as part of Microsoft's Patch Tuesday, coinciding with Valentine's Day.
5
How many zero-day vulnerabilities were reported in this article?
The article reports on six zero-day vulnerabilities that were exploited before they were patched.