Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Publicis forms new Influential Sports squad to hone its skills in the white-hot sports media arena

    In the age of AI content, The Super Bowl felt old-fashioned

    ‘The billable hour does not allow for any meaningful innovation’: S4 Capital builds subscription model for the AI age

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026

      To avoid accusations of AI cheating, college students are turning to AI

      January 29, 2026

      ChatGPT can embrace authoritarian ideas after just one prompt, researchers say

      January 24, 2026
    • Business

      New VoidLink malware framework targets Linux cloud servers

      January 14, 2026

      Nvidia Rubin’s rack-scale encryption signals a turning point for enterprise AI security

      January 13, 2026

      How KPMG is redefining the future of SAP consulting on a global scale

      January 10, 2026

      Top 10 cloud computing stories of 2025

      December 22, 2025

      Saudia Arabia’s STC commits to five-year network upgrade programme with Ericsson

      December 18, 2025
    • Crypto

      HBAR Shorts Face $5 Million Risk if Price Breaks Key Level

      February 10, 2026

      Ethereum Holds $2,000 Support — Accumulation Keeps Recovery Hopes Alive

      February 10, 2026

      Miami Mansion Listed for 700 BTC as California Billionaire Tax Sparks Relocations

      February 10, 2026

      Solana Drops to 2-Year Lows — History Suggests a Bounce Toward $100 is Incoming

      February 10, 2026

      Bitget Cuts Stock Perps Fees to Zero for Makers Ahead of Earnings Season, Expanding Access Across Markets

      February 10, 2026
    • Technology

      Publicis forms new Influential Sports squad to hone its skills in the white-hot sports media arena

      February 11, 2026

      In the age of AI content, The Super Bowl felt old-fashioned

      February 11, 2026

      ‘The billable hour does not allow for any meaningful innovation’: S4 Capital builds subscription model for the AI age

      February 11, 2026

      Digiday ranks the best and worst Super Bowl 2026 ads

      February 11, 2026

      YouTube’s upmarket TV push still runs on mid-funnel DNA

      February 11, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»February Patch Tuesday: Microsoft drops six zero-days
    Technology

    February Patch Tuesday: Microsoft drops six zero-days

    TechAiVerseBy TechAiVerseFebruary 11, 2026No Comments4 Mins Read3 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    February Patch Tuesday: Microsoft drops six zero-days
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    February Patch Tuesday: Microsoft drops six zero-days

    Microsoft releases patches for six zero-day flaws in its latest monthly update, many of them related to security feature bypass issues.

    By

    • Alex Scroxton,
      Security Editor

    Published: 10 Feb 2026 22:10

    Microsoft has released fixes for six newly-classified zero-day common vulnerabilities and exposures (CVEs) on the second monthly Patch Tuesday of 2026, amid a release comprising over 50 flaws that run the full gamut of Microsoft’s product suite.

    Although the total number of flaws is down by about half on January’s bumper crop, it is about on par for this time of year, explained Dustin Childs of Trend Micro’s Zero Day Initiative (ZDI), however, he added, the number under active attack is “extraordinarily high”.

    Indeed, with all six zero-days under active exploitation in the wild, and three of them already made public, Childs noted: “We’ll see if we’re on our way to another ‘hot exploit summer’ as we saw a few years ago or if this is just an aberration.”

    The three ‘classic’ zero-days are all security feature bypass (SFB) vulnerabilities, tracked variously as CVE-2026-21510 in Windows SmartScreen, CVE-2026-21514 in Microsoft Word, and CVE-2026-21513 in Internet Explorer.

    The three zero-days for which exploit proofs of concept (PoCs) have not yet been made public are tracked as CVE-2026-21519, an elevation of privilege (EoP) flaw in Desktop Window Manager, CVE-2026-21525, a denial of service (DoS) flaw in Windows Remote Access Connection Manager, and finally, CVE-2026-21533, an EoP flaw in Windows Remote Desktop Services.

    Seth Hoyt, senior security engineer at endpoint security platform Automox, said the flaw in Windows Shell was particularly dangerous because its effect is essentially to neutralise the important SmartScreen feature in Microsoft Defender.

    “SmartScreen serves as a critical checkpoint: when you download an executable or document, it prompts you to confirm whether you trust the source. This bypass removes that checkpoint entirely,” he said. “Files from the internet execute without triggering the usual warning dialog, giving attackers a clean path to run malicious code once a user clicks a phishing link.

    “The attack still requires user interaction, but with one less security prompt in the way, the barrier to successful exploitation drops considerably,” said Hoyt.

    Beyond patching, he advised defenders to be alert to unusual cmd.exe or PowerShell activity in the wake of a file download, or odd processes spawning from files in Downloads or temporary directories that do not have corresponding SmartScreen events logged. It is also worth applying endpoint hardening measures such as Attack Surface Reduction rules.

    Hoyt added that CVE-2026-21514 works in a similar fashion and should be treated in the same terms.

    Meanwhile, Jack Bicer, vulnerability research director at patch management specialist Action1, turned to the MSHTML Framework flaw in Internet Explorer, CVE-2026-21513.

    “The MSHTML Framework [is] a core component used by Windows and multiple applications to render HTML content,” he said. “[CVE-2026-21513] is caused by a protection mechanism failure that allows attackers to bypass execution prompts when users interact with malicious files. A crafted file can silently bypass Windows security prompts and trigger dangerous actions with a single click.

    “Exploitation occurs over the network and requires user interaction, such as opening a malicious HTML file or clicking a shortcut delivered via email, link, or download. No privileges are required by the attacker,” he added.

    Bicer explained that such SFB flaws significantly increase the success rate of phishing and campaigns that ultimately have impacts far beyond embarrassment for the one person who accidentally clicked on something without thinking. In enterprise environments they become a gateway to a whole host of nasties, including unauthorised code execution, malware and ransomware deployment, credential and data theft, and other compromises.

    Deep dependence

    Coming a month after January’s blockbuster Patch Tuesday, Cory Simpson, senior advisor to the Cyberspace Solarium Commission and a former advisor to the US Special Operations Command, said that 2026 was already off to a concerning start.

    He described the situation on the ground as standing in “stark contrast” to the picture painted in Microsoft’s November 2025 Secure Future Initiative report, which hailed the idea of ‘security above all else’ as a guiding principle at Redmond.

    “Patch volumes like today’s, six active zero-days, reflect the structural risk created by deep dependence on Microsoft across enterprise environments,” Simpson told Computer Weekly.

    “Security leadership starts with baseline hygiene and extends to resilience-by-design: diversified dependencies, reduced concentration risk, and architectures built to operate under persistent vulnerability discovery,” he said.

    Read more on Application security and coding requirements


    • SolarWinds RCE bug makes Cisa list as exploitation spreads

      By: Alex Scroxton


    • News brief: Patch critical and high-severity vulnerabilities now

      By: Staff report


    • Microsoft patches 112 CVEs on first Patch Tuesday of 2026

      By: Alex Scroxton


    • Microsoft patched over 1,100 CVEs in 2025

      By: Alex Scroxton

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleResearchers delve inside new SolarWinds RCE attack chain
    Next Article Nvidia releases DreamDojo, a robot ‘world model’ trained on 44,000 hours of human video
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Publicis forms new Influential Sports squad to hone its skills in the white-hot sports media arena

    February 11, 2026

    In the age of AI content, The Super Bowl felt old-fashioned

    February 11, 2026

    ‘The billable hour does not allow for any meaningful innovation’: S4 Capital builds subscription model for the AI age

    February 11, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025664 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025250 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025151 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025111 Views
    Don't Miss
    Technology February 11, 2026

    Publicis forms new Influential Sports squad to hone its skills in the white-hot sports media arena

    Publicis forms new Influential Sports squad to hone its skills in the white-hot sports media…

    In the age of AI content, The Super Bowl felt old-fashioned

    ‘The billable hour does not allow for any meaningful innovation’: S4 Capital builds subscription model for the AI age

    Digiday ranks the best and worst Super Bowl 2026 ads

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Publicis forms new Influential Sports squad to hone its skills in the white-hot sports media arena

    February 11, 20262 Views

    In the age of AI content, The Super Bowl felt old-fashioned

    February 11, 20262 Views

    ‘The billable hour does not allow for any meaningful innovation’: S4 Capital builds subscription model for the AI age

    February 11, 20262 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    This new Roomba finally solves the big problem I have with robot vacuums

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.