Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryactively-exploited-vulnerabilityendpoint-software-vulnerability

February Patch Releases Address Actively Exploited Windows Zero-Days and High-Severity Chrome Vulnerabilities

Updated 3mo agoFirst seen Feb 11, 20262 sources

A broad set of February security updates shipped across major vendors, led by Microsoft releasing fixes for 59 Windows flaws, including six actively exploited zero-days affecting multiple Windows components with impacts spanning security feature bypass, privilege escalation, and denial-of-service. Adobe also issued updates across creative products (e.g., Audition, After Effects, InDesign, Lightroom Classic), stating it is not aware of in-the-wild exploitation of the addressed issues.

SAP published fixes for two critical vulnerabilities: CVE-2026-0488 (CVSS 9.9), a code/SQL injection issue in SAP CRM and SAP S/4HANA that could enable arbitrary SQL execution and full database compromise, and CVE-2026-0509 (CVSS 9.6), a missing authorization check in SAP NetWeaver AS ABAP/ABAP Platform that could allow low-privileged users to perform background RFC actions without required S_RFC authorization (mitigations include a kernel update and profile parameter changes). Separately, Google/Chromium released Chrome/Chromium 144 updates addressing 11 CVEs including high-severity issues in V8 and Blink (notably CVE-2026-1220, a V8 race condition), with no confirmed public reporting of active exploitation for those Chrome bugs at the time of publication; Intel and Google also reported multiple vulnerabilities in Intel TDX 1.5 (including CVE-2025-32007, CVE-2025-27940, CVE-2025-30513, CVE-2025-27572, CVE-2025-32467).

Share:
February Patch Releases Address Actively Exploited Windows Zero-Days and High-Severity Chrome Vulnerabilities
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Feb 10, 20264mo ago

Multiple vendors publish February 2026 security advisories

More than 60 software vendors released security fixes across operating systems, cloud services, browsers, enterprise software, and network platforms in the February 2026 patch cycle. The advisories included high- and critical-severity issues in products from vendors such as Cisco, Palo Alto Networks, VMware, Zoom, ServiceNow, and WordPress plugin developers.

Intel and Google assess Intel TDX 1.5 and disclose multiple weaknesses

Intel and Google jointly evaluated Intel TDX 1.5 and reported five CVEs along with additional weaknesses and improvement recommendations. Their findings cited increased trusted computing base complexity as a security concern.

SAP releases fixes for critical CRM, S/4HANA, and NetWeaver issues

SAP issued patches for two critical vulnerabilities, including a code injection flaw affecting SAP CRM and SAP S/4HANA and an authorization-check weakness in SAP NetWeaver ABAP components. Onapsis also published remediation guidance tied to the SAP updates.

Adobe publishes security updates for Creative Cloud products

Adobe released patches for several Creative Cloud products during the February 2026 security update cycle. The company said it was not aware of any in-the-wild exploitation affecting the addressed issues at the time of release.

Microsoft Patch Tuesday fixes 59 flaws, including six exploited zero-days

Microsoft's February 2026 Patch Tuesday addressed 59 vulnerabilities, including six actively exploited zero-days in Windows components. The flaws enabled impacts such as security feature bypass, privilege escalation, and denial-of-service.

Google ships Chrome 144 security updates

Google released Chromium/Chrome 144 updates fixing 11 vulnerabilities, including multiple high-severity issues in V8 and Blink. The fixes were highlighted in February 2026 patch coverage as part of the broader vendor update cycle.

Microsoft issues out-of-band fix for exploited Office zero-day

Microsoft released an out-of-band patch for CVE-2026-21509, an actively exploited Microsoft Office zero-day. Coverage described it as one of the limited cases in the February update cycle with confirmed in-the-wild exploitation.

Jan 1, 20266mo ago

Oracle releases January 2026 Critical Patch Update

Oracle published its January 2026 Critical Patch Update, delivering 337 security fixes across its product portfolio. The update was later referenced in February patch-roundup coverage as part of the broader wave of vendor advisories.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

99 LINKEDOpen in app
Affected products
25 linked
MongodbAndroidServicenowDrupalAmazon LinuxZoomSplunkGrafanaSuse LinuxMongodbUbuntuGitlabAndroidGrafanaPixelPixelRed Hat Enterprise LinuxOracle LinuxVmwareArch LinuxSolarwindsRocky LinuxSap S/4hanaSap CrmUbuntu
Organizations
67 linked
Mitsubishi Electric CorporationMozillaAvevaHitachi EnergyDell TechnologiesPhoenix ContactCheck Point Software TechnologiesFujifilmRockwell AutomationCisco SystemsRed HatSplunkLenovoNvidiaAmazon Web ServicesSuper Micro ComputerHikvisionZyxel CommunicationsFujitsuGrafana LabsDevolutionsABBSchneider ElectricSamsung ElectronicsWatchGuard TechnologiesSAPGitLabCommvaultInternational Business MachinesSiemensMoxaMongodbDassault SystemesASUSTP-LinkCanonZoom CommunicationsAdvanced Micro DevicesSuseQNAP SystemsSolarWindsSynologyFortinetIvantiD-LinkFoxit SoftwareAutomationdirectZoho CorporationQualcommF5CanonicalRicohServicenowCitrix SystemsAppleConnectwiseBroadcomMicrosoft CorporationGIGABYTE TechnologyAdobeHewlett Packard EnterpriseIntelOnapsisMediaTekdormakabaGoogleAmerican Megatrends International
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.