Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitywidely-deployed-product-advisoryendpoint-software-vulnerabilityinitial-access-method

Actively exploited Microsoft zero-days patched in February security updates

Updated 3mo agoFirst seen Feb 11, 20263 sources

Microsoft disclosed and patched multiple actively exploited vulnerabilities as part of its February security updates, including a Microsoft Word security feature bypass tracked as CVE-2026-21514. The Word flaw (CVSS 7.8; CWE-807) allows attackers to bypass Object Linking and Embedding (OLE)-related mitigations by abusing how Word makes security decisions based on untrusted inputs; exploitation is described as requiring a crafted document and user interaction (e.g., opening a phishing-delivered file) while avoiding typical prompts such as Protected View or “Enable Content” warnings.

Microsoft also addressed an in-the-wild exploited Windows Desktop Window Manager (dwm.exe) elevation-of-privilege vulnerability, CVE-2026-21519 (CVSS 7.8), which can allow a local attacker to escalate from a standard user context to SYSTEM. The February update review also lists additional exploited issues patched in the same release, including security feature bypasses in Windows Shell (CVE-2026-21510) and Internet Explorer (CVE-2026-21513), plus other exploited vulnerabilities (e.g., Windows Remote Desktop Services EoP CVE-2026-21533), underscoring that defenders should prioritize rapid deployment of the February fixes across affected Windows and Office estates.

Share:
Actively exploited Microsoft zero-days patched in February security updates
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Mar 3, 20264mo ago

CISA sets federal patch deadline for Word zero-day

CISA set a 2026-03-03 deadline for U.S. federal civilian agencies to remediate CVE-2026-21514 after it was disclosed as actively exploited. The directive elevated urgency around patching the Microsoft Word zero-day.

Feb 10, 20264mo ago

Microsoft patches exploited DWM zero-day CVE-2026-21519 in February updates

On 2026-02-10, Microsoft addressed CVE-2026-21519 in the February 2026 security update, fixing an actively exploited Windows Desktop Window Manager flaw that could allow local privilege escalation to SYSTEM. The issue affects multiple Windows 10, Windows 11, and Windows Server versions, with no workaround other than patching.

Microsoft issues Office fixes for Word zero-day CVE-2026-21514

Microsoft released Click-to-Run updates for affected Windows and Mac Office products to address CVE-2026-21514, including version 16.106.26020821. The fixes cover multiple Office product lines such as Microsoft 365 Apps for Enterprise and Office LTSC 2021/2024.

Microsoft discloses actively exploited Word zero-day CVE-2026-21514

On 2026-02-10, Microsoft disclosed CVE-2026-21514, a Microsoft Word security feature bypass flaw that abuses untrusted input handling to bypass OLE mitigations for malicious COM/OLE controls. The vulnerability was reported as actively exploited in the wild and can be triggered when a user opens a specially crafted Office document.

Microsoft's February 2026 security updates disclose multiple exploited zero-days

On 2026-02-10, Microsoft's February 2026 security release was reviewed publicly, listing several vulnerabilities as exploited in the wild, including Microsoft Word security feature bypass CVE-2026-21514 and Desktop Window Manager elevation-of-privilege CVE-2026-21519. The release also covered fixes across Windows, Office, Azure, and other Microsoft products.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

93 LINKEDOpen in app
Vulnerabilities
61 linked
Heap-based buffer overflow in libjpeg-turbo merged upsampling (h2v2_merged_upsample_internal)Windows Hyper-V Remote Code Execution VulnerabilityType Confusion in V8 in Google ChromeHeap Buffer Overflow in libvpx in Google ChromeAzure Function Information Disclosure VulnerabilityUntitledUntitledMicrosoft Edge for Android UI Misrepresentation Spoofing VulnerabilityWindows Subsystem for Linux Race Condition Privilege EscalationUntitledRCE in Azure Local via improper certificate validation (CVE-2026-21228)Information disclosure in Azure IoT Explorer via unrestricted IP bindSpoofing via Deserialization of Untrusted Data in Microsoft OutlookWindows Remote Access Connection Manager NULL Pointer Dereference DoSMicrosoft Word OLE Security Feature BypassLocal EoP in Windows HTTP.sys via untrusted pointer dereferenceWindows Shell SmartScreen and Security Prompt Bypass via Malicious LNK/LinkWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityCode injection RCE in Microsoft Defender for Linux (Defender for Endpoint Linux extension)Windows Storage Elevation of Privilege VulnerabilityWindows LDAP Null Pointer Dereference Denial of ServiceInformation Disclosure in Azure Compute Gallery / Microsoft ACI Confidential ContainersWindows Cluster Client Failover Use-After-Free Elevation of PrivilegeDesktop Window Manager Type Confusion Local Privilege EscalationRCE via unsafe deserialization in Azure SDK (Azure SDK for Python)Heap-based Buffer Overflow in Windows Hyper-VTOCTOU race condition RCE in GitHub Copilot and Visual Studio CodeWindows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability.NET System.Security.Cryptography.Cose spoofing / security feature bypassMicrosoft MSHTML Framework Security Feature BypassCommand Injection Privilege Escalation in GitHub Copilot and Visual StudioCommand Injection RCE in GitHub Copilot and Visual StudioWindows Remote Desktop Services Elevation of PrivilegeCommand Injection in GitHub Copilot and Visual Studio Code mcp.json HandlingWindows Hyper-V Security Feature Bypass VulnerabilityRemote Code Execution in Windows Notepad App via Markdown Link HandlingWindows NTLM searchConnector-ms NTLM Response Disclosure / SpoofingWindows Subsystem for Linux Use-After-Free Privilege EscalationXSS in Azure HDInsights (network spoofing)Spoofing in Microsoft Exchange Server InterceptorSmtpAgentLocal privilege escalation via link following in Windows App for MacWindows Kernel Elevation of Privilege Race ConditionLocal information disclosure in Microsoft Office Excel (improper input validation)Windows HTTP.sys Elevation of Privilege VulnerabilityElevation of Privilege in Windows Ancillary Function Driver for WinSockOut-of-bounds read information disclosure in Microsoft Office ExcelCommand injection RCE in GitHub Copilot for JetBrainsMailslot File System Elevation of Privilege VulnerabilityPrivilege Escalation in Windows Connected Devices Platform ServiceWindows Graphics Component Use-After-Free Privilege EscalationHeap-based Buffer Overflow in Microsoft Graphics ComponentWindows GDI+ Buffer Over-read Denial of Service VulnerabilityWindows HTTP.sys Elevation of Privilege VulnerabilityRCE in Microsoft Power BI via improper input validationWindows Kernel Heap-Based Buffer Overflow Privilege EscalationWindows Kernel Information Disclosure VulnerabilityCommand Injection in Azure Compute Gallery / Microsoft ACI Confidential ContainersMicrosoft Outlook Spoofing VulnerabilityWindows Kernel Heap-Based Buffer Overflow Privilege EscalationRemote Code Execution in Windows Hyper-VUntitled
Affected products
30 linked
Gdi+Azure Devops ServerAzure FunctionsNetGithub CopilotAzure ArcInternet ExplorerVisual Studio CodeWindows Subsystem For LinuxPower BiNetChromiumChromiumWindows KernelWindows Hyper-VDesktop Window ManagerWindows ShellWindows NtlmWindows Http.SysAzure Sdk For PythonAzure Front DoorWindows Ancillary Function Driver For WinsockWindows Connected Devices Platform ServiceWindows StorageAzure Container Instances (Aci) Confidential ContainersAzure LocalAzure Iot ExplorerAzure HdinsightWindows NotepadWindows Graphics Component
Organizations
2 linked
Red HatMicrosoft Corporation
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Actively exploited Microsoft zero-days patched in February security updates | Mallory