What’s New Wednesday: February 2026 February 11, 2026 – Posted in: Cyber Security, IT Support, What's New Wednesdays – Tags: , , , , ,

Welcome to Februrary 2026 this month Microsoft has released patches for 58 flaws, 6 of which are actively exploited zero-days. It’s a good idea to restart your PC today, and we may restart some of your servers overnight this week if a patch requires it.

NEW THIS WEDNESDAY

Overall Microsoft patched:

  • 25 Elevation of Privilege Vulnerabilities
  • 5 Security Feature Bypass vulnerabilities
  • 12 Remote Code Execution Vulnerabilities
  • 6 Information Disclosure Vulnerabilities
  • 3 Denial of Service Vulnerabilities
  • 7 Spoofing Vulnerability

There were 6 actively exploited zero-day vulnerabilities patched:

CVE-2026-21510 – Windows Shell Security Feature Bypass Vulnerability

A flaw that allowed an attacker who convinced a user to open a malicious link or shortcut file to bypass security prompts by exploiting improper handling in Windows Shell components, allowing malicious content to execute without user warning or consent.

CVE-2026-21513 – MSHTML Framework Security Feature Bypass Vulnerability

An actively exploited MSHTML security feature bypass flaw in Windows that allowed an unauthorized attacker to bypass a security feature over a network.

CVE-2026-21514 – Microsoft Word Security Feature Bypass Vulnerability

If a user opens a malicious office file an attacker could bypass OLE mitigations in Microsoft 365.

CVE-2026-21519 – Desktop Window Manager Elevation of Privilege Vulnerability

An actively exploited elevation of privileges flaw in the Desktop Window Manager that allowed an attacker to gain SYSTEM privileges.

CVE-2026-21525 – Windows Remote Access Connection Manager Denial of Service Vulnerability

An actively exploited denial of service flaw in the Windows Remote Access Connection Manager.

CVE-2026-21533 – Windows Remote Desktop Services Elevation of Privilege Vulnerability

A flaw in privilege management in Windows Remote Desktop allowed an authorized attacker to elevate privileges locally.

Releases from other software providers include:

  • Adobe – updates for InDesign, Illustrator, InCopy, Bridge, Substance 3D Modeler, Substance 3D Stager, Substance 3D Painter, Substance 3D Sampler, Coldfusion, and Substance 3D Designer.
  • BeyondTrust – updates for a critical RCE flaw in its Remote Support (RS) and Privileged Remote Access (PRA) software.
  • CISA – a binding operational directive requiring federal agencies to remove network edge devices that have reached the end of support.
  • Cisco – security updates for Secure Web Appliance, Cisco Meeting Management, and more.
  • Fortinet – security updates for FortiOS and FortiSandbox.
  • Google – Android’s February security bulletin, which includes no security fixes.
  • n8n – a patch bypass for the previously fixed CVE-2025-68613 RCE flaw.
  • SAP – security updates for multiple products, including fixes for two critical vulnerabilities.

FULL LIST OF KNOWN PATCHES

Vulnerable Service CVE ID CVE Title Severity
.NET CVE-2026-21218 .NET Spoofing Vulnerability Important
Azure Arc CVE-2026-24302 Azure Arc Elevation of Privilege Vulnerability Critical
Azure Compute Gallery CVE-2026-23655 Microsoft ACI Confidential Containers Information Disclosure Vulnerability Critical
Azure Compute Gallery CVE-2026-21522 Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability Critical
Azure DevOps Server CVE-2026-21512 Azure DevOps Server Cross-Site Scripting Vulnerability Important
Azure Front Door (AFD) CVE-2026-24300 Azure Front Door Elevation of Privilege Vulnerability Critical
Azure Function CVE-2026-21532 Azure Function Information Disclosure Vulnerability Critical
Azure HDInsights CVE-2026-21529 Azure HDInsight Spoofing Vulnerability Important
Azure IoT SDK CVE-2026-21528 Azure IoT Explorer Information Disclosure Vulnerability Important
Azure Local CVE-2026-21228 Azure Local Remote Code Execution Vulnerability Important
Azure SDK CVE-2026-21531 Azure SDK for Python Remote Code Execution Vulnerability Important
Desktop Window Manager CVE-2026-21519 Desktop Window Manager Elevation of Privilege Vulnerability Important
Github Copilot CVE-2026-21516 GitHub Copilot for Jetbrains Remote Code Execution Vulnerability Important
GitHub Copilot and Visual Studio CVE-2026-21523 GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability Important
GitHub Copilot and Visual Studio CVE-2026-21256 GitHub Copilot and Visual Studio Remote Code Execution Vulnerability Important
GitHub Copilot and Visual Studio CVE-2026-21257 GitHub Copilot and Visual Studio Elevation of Privilege Vulnerability Important
GitHub Copilot and Visual Studio Code CVE-2026-21518 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability Important
Mailslot File System CVE-2026-21253 Mailslot File System Elevation of Privilege Vulnerability Important
Microsoft Defender for Linux CVE-2026-21537 Microsoft Defender for Endpoint Linux Extension Remote Code Execution Vulnerability Important
Microsoft Edge (Chromium-based) CVE-2026-1861 Chromium: CVE-2026-1861 Heap buffer overflow in libvpx Unknown
Microsoft Edge (Chromium-based) CVE-2026-1862 Chromium: CVE-2026-1862 Type Confusion in V8 Unknown
Microsoft Edge for Android CVE-2026-0391 Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability Moderate
Microsoft Exchange Server CVE-2026-21527 Microsoft Exchange Server Spoofing Vulnerability Important
Microsoft Graphics Component CVE-2026-21246 Windows Graphics Component Elevation of Privilege Vulnerability Important
Microsoft Graphics Component CVE-2026-21235 Windows Graphics Component Elevation of Privilege Vulnerability Important
Microsoft Office Excel CVE-2026-21261 Microsoft Excel Information Disclosure Vulnerability Important
Microsoft Office Excel CVE-2026-21258 Microsoft Excel Information Disclosure Vulnerability Important
Microsoft Office Excel CVE-2026-21259 Microsoft Excel Elevation of Privilege Vulnerability Important
Microsoft Office Outlook CVE-2026-21260 Microsoft Outlook Spoofing Vulnerability Important
Microsoft Office Outlook CVE-2026-21511 Microsoft Outlook Spoofing Vulnerability Important
Microsoft Office Word CVE-2026-21514 Microsoft Word Security Feature Bypass Vulnerability Important
MSHTML Framework CVE-2026-21513 MSHTML Framework Security Feature Bypass Vulnerability Important
Power BI CVE-2026-21229 Power BI Remote Code Execution Vulnerability Important
Role: Windows Hyper-V CVE-2026-21244 Windows Hyper-V Remote Code Execution Vulnerability Important
Role: Windows Hyper-V CVE-2026-21255 Windows Hyper-V Security Feature Bypass Vulnerability Important
Role: Windows Hyper-V CVE-2026-21248 Windows Hyper-V Remote Code Execution Vulnerability Important
Role: Windows Hyper-V CVE-2026-21247 Windows Hyper-V Remote Code Execution Vulnerability Important
Windows Ancillary Function Driver for WinSock CVE-2026-21236 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Important
Windows Ancillary Function Driver for WinSock CVE-2026-21241 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Important
Windows Ancillary Function Driver for WinSock CVE-2026-21238 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Important
Windows App for Mac CVE-2026-21517 Windows App for Mac Installer Elevation of Privilege Vulnerability Important
Windows Cluster Client Failover CVE-2026-21251 Cluster Client Failover (CCF) Elevation of Privilege Vulnerability Important
Windows Connected Devices Platform Service CVE-2026-21234 Windows Connected Devices Platform Service Elevation of Privilege Vulnerability Important
Windows GDI+ CVE-2026-20846 GDI+ Denial of Service Vulnerability Important
Windows HTTP.sys CVE-2026-21240 Windows HTTP.sys Elevation of Privilege Vulnerability Important
Windows HTTP.sys CVE-2026-21250 Windows HTTP.sys Elevation of Privilege Vulnerability Important
Windows HTTP.sys CVE-2026-21232 Windows HTTP.sys Elevation of Privilege Vulnerability Important
Windows Kernel CVE-2026-21231 Windows Kernel Elevation of Privilege Vulnerability Important
Windows Kernel CVE-2026-21222 Windows Kernel Information Disclosure Vulnerability Important
Windows Kernel CVE-2026-21239 Windows Kernel Elevation of Privilege Vulnerability Important
Windows Kernel CVE-2026-21245 Windows Kernel Elevation of Privilege Vulnerability Important
Windows LDAP – Lightweight Directory Access Protocol CVE-2026-21243 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability Important
Windows Notepad App CVE-2026-20841 Windows Notepad App Remote Code Execution Vulnerability Important
Windows NTLM CVE-2026-21249 Windows NTLM Spoofing Vulnerability Important
Windows Remote Access Connection Manager CVE-2026-21525 Windows Remote Access Connection Manager Denial of Service Vulnerability Moderate
Windows Remote Desktop CVE-2026-21533 Windows Remote Desktop Services Elevation of Privilege Vulnerability Important
Windows Shell CVE-2026-21510 Windows Shell Security Feature Bypass Vulnerability Important
Windows Storage CVE-2026-21508 Windows Storage Elevation of Privilege Vulnerability Important
Windows Subsystem for Linux CVE-2026-21237 Windows Subsystem for Linux Elevation of Privilege Vulnerability Important
Windows Subsystem for Linux CVE-2026-21242 Windows Subsystem for Linux Elevation of Privilege Vulnerability Important
Windows Win32K – GRFX CVE-2023-2804 Red Hat, Inc. CVE-2023-2804: Heap Based Overflow libjpeg-turbo Important

GLOSSARY

  • Authentication – proving who you are so you can be given access to what you need/have rights to.
  • MFA – multi-factor authentication, proving who you are in multiple ways, something you know (like a password or pin), something you are (a fingerprint or retina scan), something you have (like your phone – proved with a code).
  • Vulnerability – a defect in software that could allow an attacker to gain control of a system or service.
  • Patch – a change to a piece of software, released after sale, to fix a problem or add a feature.
  • Zero Day – Microsoft classifies a vulnerability as a zero-day if it is publicly disclosed or actively exploited with no official fix available.
  • Actively Exploited – an actively exploited vulnerability is one that is being used by malicious actors.
  • DDOS / DOS – (Distributed) Denial of Service attack, a method of swamping a service or server with so many false queries at once that it is forced offline.
  • Disclosed – a disclosed vulnerability is one that the software creators have published, meaning that it can be easily found out about by anyone who knows where to look.
  • CVE ID – CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws, the ID is the number assigned to that vulnerability.
  • Severity – a disclosed vulnerability is one that the software creators have published, meaning that it can be easily found out about by anyone who knows where to look.
  • Security Feature Bypass Vulnerabilities – allow for intruders to bypass security features such as password protection or MFA.
  • Remote Code Execution Vulnerabilities – allow people to remotely trigger potentially malicious code on your device.
  • Information Disclosure Vulnerabilities – allow the wrong people access to your data.
  • Denial of Service Vulnerabilities – allow a DOS/DDOS attack to succeed.
  • Spoofing Vulnerabilities – allow someone to pretend to be you/your systems.

If you have any concerns about cybersecurity, or would like to discuss any other IT Support needs you might have please give us a call on 01245 265100 or email us at . To stay up to date with our regular What’s New Wednesday emails and receive industry news straight to your inbox, subscribe to our newsletters in the top right.