Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryactively-exploited-vulnerabilityendpoint-software-vulnerabilitypatch-regression

February 2026 Patch Tuesday Security Updates for Microsoft Windows and Adobe Products

Updated 3mo agoFirst seen Feb 10, 20262 sources

Microsoft and Adobe released their February 2026 Patch Tuesday security updates, with Microsoft addressing 58 vulnerabilities and reporting six actively exploited zero-day flaws as part of the month’s fixes. Microsoft also continued its rollout of replacements for expiring Secure Boot certificates and shipped the Windows 10 KB5075912 Extended Security Update (ESU) for eligible systems (e.g., Windows 10 Enterprise LTSC and ESU-enrolled devices), updating builds to 19045.6937 (Windows 10) and 19044.6937 (LTSC 2021). In addition to security fixes, KB5075912 includes reliability remediation for an issue where some Secure Launch-capable PCs with VSM enabled could not shut down or hibernate after January 2026 security updates.

Adobe published nine security bulletins covering 44 CVEs across products including After Effects, Audition, InDesign, Adobe Bridge, Lightroom Classic, and multiple Substance 3D applications, with several issues rated Critical and potentially leading to code execution (notably in After Effects and Substance 3D Stager). Adobe stated that, at release time, none of the addressed vulnerabilities were listed as publicly known or under active attack, contrasting with Microsoft’s disclosure of in-the-wild exploitation for multiple zero-days in the same Patch Tuesday cycle.

Share:
February 2026 Patch Tuesday Security Updates for Microsoft Windows and Adobe Products
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 10, 20264mo ago

Microsoft continues phased rollout of new Secure Boot certificates

Microsoft said it was continuing a phased deployment of replacement Secure Boot certificates ahead of the June 2026 expiration of 2011-era certificates. The rollout uses targeting data to send the certificates only to devices showing sufficient successful update signals.

Microsoft releases Windows 10 ESU update KB5075912

Microsoft released Windows 10 KB5075912 as the February 2026 Extended Security Update for Windows 10 Enterprise LTSC and systems enrolled in the ESU program, updating supported systems to builds 19045.6937 and 19044.6937. The update included the broader Patch Tuesday security fixes, including six actively exploited zero-days, plus fixes for shutdown, File Explorer, and GPU-related issues.

Microsoft discloses six actively exploited zero-days in February Patch Tuesday

At release, Microsoft reported that six vulnerabilities fixed in the February 2026 updates were being exploited in the wild, with three also publicly known. The exploited issues included SmartScreen, Windows Shell, Word, Internet Explorer-related, elevation-of-privilege, and Remote Access Connection Manager flaws.

Microsoft issues February 2026 Patch Tuesday fixes for 58 CVEs

Microsoft released its February 2026 Patch Tuesday security updates covering 58 new CVEs, or 62 including third-party and Chromium items, across Windows, Office, Azure, Edge, .NET/Visual Studio, Exchange, Hyper-V, WSL, and other components. Five of the flaws were rated Critical.

Adobe releases February 2026 security updates for 44 CVEs

Adobe published nine security bulletins covering 44 CVEs across Creative Cloud products and related components, including Critical code-execution flaws in several products. Adobe said none of the vulnerabilities were publicly known or under active attack at release time, and assigned all updates deployment priority 3.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

16 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.