Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitywidely-deployed-product-advisoryproof-of-concept-releaselateral-movement-method

Microsoft February Patch Tuesday Fixes Actively Exploited Zero-Days Including Windows RDS Privilege Escalation

Updated 3mo agoFirst seen Feb 11, 202610 sources

Microsoft’s February 2026 Patch Tuesday shipped fixes for 58 vulnerabilities across Windows, Office, and related components, including six zero-days reported as actively exploited. Reported zero-days included CVE-2026-21533 (Windows Remote Desktop Services elevation of privilege), CVE-2026-21510 (Windows Shell security feature bypass involving SmartScreen/Mark-of-the-Web), CVE-2026-21513 and CVE-2026-21514 (Office/MSHTML mitigation bypasses requiring user interaction), and CVE-2026-21525 (Windows Remote Access Connection Manager DoS). Coverage of the release emphasized that elevation-of-privilege issues were the largest category in the update set, and that organizations should prioritize rapid deployment given in-the-wild exploitation claims.

For CVE-2026-21533 (CVSS 7.8, Important), reporting cited CrowdStrike observations of an exploit binary used post-compromise to reach SYSTEM by modifying a service configuration registry key to point to attacker-controlled values, enabling actions such as adding a user to the local Administrators group; the issue primarily impacts Windows systems where RDS is enabled and is positioned as a strong enabler for lateral movement in RDP-heavy environments. Separately, a January 2026-patched local privilege escalation in Windows Error Reporting, CVE-2026-20817 (CVSS 7.8), was described with technical detail and a released PoC: the WER service (wersvc.dll) allegedly failed to validate requester permissions over ALPC, allowing a standard user to trigger process creation with a SYSTEM-derived token retaining powerful privileges (e.g., SeDebugPrivilege, SeImpersonatePrivilege, SeBackupPrivilege), underscoring the broader trend of Windows local EoP bugs being leveraged for post-exploitation escalation.

Share:
Microsoft February Patch Tuesday Fixes Actively Exploited Zero-Days Including Windows RDS Privilege Escalation
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 11, 20264mo ago

CISA adds six Microsoft February flaws to the KEV catalog

CISA added six Microsoft Windows and Office vulnerabilities from the February 2026 release to its Known Exploited Vulnerabilities catalog, citing active exploitation. The agency ordered U.S. federal civilian executive branch agencies to remediate the issues by March 3, 2026, and urged private organizations to prioritize patching as well.

Feb 10, 20264mo ago

Microsoft discloses three of the exploited February flaws were publicly known

Alongside the February 2026 Patch Tuesday release, Microsoft indicated that three of the six actively exploited vulnerabilities had also been publicly disclosed. These publicly known issues were security feature bypass flaws affecting Windows Shell, MSHTML/Trident, and Microsoft Word/OLE mitigations.

Microsoft releases February 2026 Patch Tuesday updates

Microsoft released its February 2026 Patch Tuesday security updates, fixing roughly 54-61 vulnerabilities across Windows, Office, Azure, Exchange Server, and related products. The release included six vulnerabilities that Microsoft said were actively exploited in the wild, spanning security feature bypass, elevation-of-privilege, and denial-of-service issues.

0patch finds RasMan DoS exploit in a public malware repository

0patch reported discovering exploit code for CVE-2026-21525, a Windows Remote Access Connection Manager denial-of-service flaw, in a public malware repository. The finding indicated the vulnerability was already accessible to attackers before Microsoft's February 2026 fixes.

Dec 24, 20256mo ago

CrowdStrike observes exploitation of RDS zero-day CVE-2026-21533

CrowdStrike reported that an exploit binary for the Windows Remote Desktop Services elevation-of-privilege flaw CVE-2026-21533 had been used against U.S. and Canada-based entities since at least December 24, 2025. The exploit modified a service configuration registry key to gain SYSTEM-level access and perform actions such as adding a user to the local Administrators group.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

66 LINKEDOpen in app
Vulnerabilities
37 linked
Windows Remote Desktop Services Elevation of PrivilegeWindows Remote Access Connection Manager NULL Pointer Dereference DoSMicrosoft Word OLE Security Feature BypassWindows Shell SmartScreen and Security Prompt Bypass via Malicious LNK/LinkDesktop Window Manager Type Confusion Local Privilege EscalationMicrosoft MSHTML Framework Security Feature BypassWindows Kernel Elevation of Privilege Race ConditionHeap-based buffer overflow in libjpeg-turbo merged upsampling (h2v2_merged_upsample_internal)Microsoft Office Shell.Explorer.1 OLE Security Feature BypassHeap Buffer Overflow in libvpx in Google ChromeAzure Function Information Disclosure VulnerabilityUntitledUntitledMicrosoft Edge for Android UI Misrepresentation Spoofing VulnerabilityUntitledInformation disclosure in Azure IoT Explorer via unrestricted IP bindSpoofing via Deserialization of Untrusted Data in Microsoft OutlookLocal EoP in Windows HTTP.sys via untrusted pointer dereferenceCode injection RCE in Microsoft Defender for Linux (Defender for Endpoint Linux extension)Information Disclosure in Azure Compute Gallery / Microsoft ACI Confidential ContainersRCE via unsafe deserialization in Azure SDK (Azure SDK for Python).NET System.Security.Cryptography.Cose spoofing / security feature bypassCommand Injection Privilege Escalation in GitHub Copilot and Visual StudioCommand Injection RCE in GitHub Copilot and Visual StudioCommand Injection in GitHub Copilot and Visual Studio Code mcp.json HandlingWindows Hyper-V Security Feature Bypass VulnerabilityRemote Code Execution in Windows Notepad App via Markdown Link HandlingWindows NTLM searchConnector-ms NTLM Response Disclosure / SpoofingXSS in Azure HDInsights (network spoofing)Spoofing in Microsoft Exchange Server InterceptorSmtpAgentLocal information disclosure in Microsoft Office Excel (improper input validation)Out-of-bounds read information disclosure in Microsoft Office ExcelWindows GDI+ Buffer Over-read Denial of Service VulnerabilityWindows Kernel Information Disclosure VulnerabilityCommand Injection in Azure Compute Gallery / Microsoft ACI Confidential ContainersMicrosoft Outlook Spoofing VulnerabilityUntitled
Affected products
16 linked
Microsoft OfficeWindows Subsystem For Linux (Wsl)Windows Server 2016WindowsWindows 11NetWindows 10Windows Server 2012Github CopilotWindows Server 2025Windows Server 2022AzureWindows Server 2012 R2Power BiWindows Server 2019Net
Organizations
13 linked
Microsoft CorporationGoogleSecurity AffairsCrowdStrikeAutomoxThe RegisterRapid7TenableAT&TACROS SecurityOutpost24GitHubThe Hacker News
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.