February 2026 Patch Tuesday: Six Zero-Days Among 59 CVEs — Threadlinqs Intelligence
As of 2026-05-30, February 2026 Patch Tuesday: Six Zero-Days Among 59 CVEs is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 38 indicators of compromise.
Threat ID: TL-2026-0064 · Severity: CRITICAL · Status: PATCHED · Category: VULNERABILITY
Microsoft's February 2026 Patch Tuesday addresses 59 vulnerabilities including six actively exploited zero-days, three of which were publicly disclosed before patching. The zero-days span Windows
February 2026 Patch Tuesday: Six Zero-Days Among 59 CVEs — Complete Analysis
Patch Tuesday Overview:
- Total CVEs: 59
- Actively Exploited Zero-Days: 6
- Publicly Disclosed (before patch): 3 of the 6 zero-days
- Critical Severity: 5
- Important Severity: 53
- Moderate Severity: 1
- Risk Types: Elevation of Privilege 25 (42%), Remote Code Execution 12 (20%), Spoofing 8 (14%)
- Most Patched Product: Windows (32 patches), ESU (25 patches)
=== THE SIX ZERO-DAYS ===
1. CVE-2026-21533 — Windows Remote Desktop Services Elevation of Privilege
- CVSS: 7.8 (Important)
- Status: Actively exploited, NOT publicly disclosed
- Discovery: CrowdStrike identified and reported to Microsoft
- Exploitation: Modifies service configuration key, replacing with attacker-controlled key → escalate to Administrator group
- Active Since: December 24, 2025 (at minimum) — targeting US and Canada-based entities
- CrowdStrike Assessment: Public disclosure will 'almost certainly' encourage broader exploitation by threat actors possessing exploit binaries and exploit brokers
- Attack Vector: Local, Low complexity, Low privilege required, No user interaction
- Impact: High to Confidentiality, Integrity, Availability
- CrowdStrike Intel: CSA-260174
- PATCH URGENCY: CRITICAL — actively exploited for 7+ weeks before patch
2. CVE-2026-21513 — MSHTML Framework Security Feature Bypass
- CVSS: 8.8 (Important)
- Status: Actively exploited AND publicly disclosed
- Exploitation: Remote attackers bypass security prompts when executing files via malicious HTML or .lnk shortcut files. Manipulates browser and Windows Shell handling — content executes without security warnings.
- Attack Vector: Network, Low complexity, No privileges required, Requires user interaction
- Impact: High to Confidentiality, Integrity, Availability
- Affected: Windows 10, Windows 11, Windows Server 2012+
- Social Engineering: Delivered via phishing emails with HTML attachments or malicious shortcut files
- PATCH URGENCY: CRITICAL — publicly disclosed + actively exploited + low complexity
3. CVE-2026-21510 — Windows Shell Security Feature Bypass
- CVSS: 8.8 (Important)
- Status: Actively exploited AND publicly disclosed
- Exploitation: Bypasses Windows SmartScreen and Windows Shell security prompts. Malicious links or shortcut files execute without user warning or consent.
- Attack Vector: Network, Low complexity, No privileges required, Requires user interaction
- Impact: High to Confidentiality, Integrity, Availability
- Technique: Exploits improper handling in Windows Shell components
- Social Engineering: Readily exploitable through phishing and social engineering
- PATCH URGENCY: CRITICAL — SmartScreen is a critical defense layer; bypass enables unopposed malware delivery
4. CVE-2026-21514 — Microsoft Word Security Feature Bypass
- CVSS: 7.8 (Important)
- Status: Actively exploited AND publicly disclosed
- Exploitation: Bypasses OLE (Object Linking and Embedding) mitigations in Microsoft 365 and Office. Malicious Office files execute vulnerable COM/OLE controls without protection.
- Attack Vector: Local, Low complexity, No privileges required, Requires user interaction
- Impact: High to Confidentiality, Integrity, Availability
- NOT via Preview Pane: Requires user to open the file
- Social Engineering: Phishing emails with malicious Word attachments
- PATCH URGENCY: HIGH — OLE bypass enables macro-style attacks without macro warnings
5. CVE-2026-21519 — Desktop Window Manager Elevation of Privilege
- CVSS: 7.8 (Important)
- Status: Actively exploited, NOT publicly disclosed
- Exploitation: Type confusion in Desktop Window Manager (dwm.exe). Local attacker with low privileges escalates to SYSTEM.
- Attack Vector: Local, Low complexity, Low privilege required, No user interaction
- Impact: High to Confidentiality, Integrity, Availability
- Note: No proven public exploit code, but active exploitation detected — threat actors possess working exploits
- DWM runs as SYSTEM — compromise = full s
Weaknesses (CWE)
CWE-843, CWE-79, CWE-476, CWE-284, CWE-200, CWE-77, CWE-312
Target sectors: All Sectors — Windows is ubiquitous
Target regions: Global, United States, Canada (CVE-2026-21533 targeting confirmed)
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 38 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-21533, CVE-2026-21513, CVE-2026-21510, CVE-2026-21514, CVE-2026-21519, CVE-2026-21525, CVE-2026-24300, CVE-2026-24302, CVE-2026-21532, CVE-2026-21522, T1566, T1566, T1204, T1204, T1203, T1559, T1068, T1134, T1078, T1553