CVE-2026-21510Active Exploitation(microsoft / windows_10_1607)

CRITICALCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 17 mentions and remains active

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-03. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-693

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Active exploitation appears in 61 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 109 mentions across 39 observed days

What's happening

  • Active exploitation reported across 61 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 61 signals
  • Technical details provided in 76 signals
  • Disclosure: 12 classified signals
  • Peaked 37d ago at 17 mentions (2026-02-11); latest day: 1
  • 109 total mentions across 39 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_server_2012windows_server_2016windows_server_2019

2 versions affected across 13 products

Deep dive

Activity timeline109 mentions / 39d
0491317Mentions · 2026-02-10: 7Mentions · 2026-02-11: 17Mentions · 2026-02-12: 16Mentions · 2026-02-13: 5Mentions · 2026-02-14: 1Mentions · 2026-02-15: 1Mentions · 2026-02-16: 4Mentions · 2026-02-17: 3Mentions · 2026-02-18: 1Mentions · 2026-02-19: 1Mentions · 2026-02-20: 1Mentions · 2026-02-23: 1Mentions · 2026-02-25: 1Mentions · 2026-02-27: 1Mentions · 2026-03-02: 1Mentions · 2026-03-04: 1Mentions · 2026-03-09: 1Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-03-22: 1Mentions · 2026-03-27: 1Mentions · 2026-04-11: 1Mentions · 2026-04-14: 1Mentions · 2026-04-16: 1Mentions · 2026-04-27: 3Mentions · 2026-04-28: 8Mentions · 2026-04-29: 2Mentions · 2026-05-04: 2Mentions · 2026-05-06: 1Mentions · 2026-05-07: 2Mentions · 2026-05-13: 3Mentions · 2026-05-14: 1Mentions · 2026-05-24: 1Mentions · 2026-05-25: 1Mentions · 2026-05-27: 5Mentions · 2026-05-30: 2Mentions · 2026-06-13: 2Mentions · 2026-06-15: 5Mentions · 2026-07-14: 1PoC Mentioned / Linked · 2026-03-02: 1PoC Mentioned / Linked · 2026-05-07: 1PoC Mentioned / Linked · 2026-05-13: 1PoC Mentioned / Linked · 2026-07-14: 1Exploit Tool / Code · 2026-03-02: 1Exploit Tool / Code · 2026-05-13: 2Exploit Tool / Code · 2026-07-14: 1Active Exploitation · 2026-02-10: 3Active Exploitation · 2026-02-11: 13Active Exploitation · 2026-02-12: 7Active Exploitation · 2026-02-13: 4Active Exploitation · 2026-02-14: 1Active Exploitation · 2026-02-16: 3Active Exploitation · 2026-02-17: 1Active Exploitation · 2026-03-02: 1Active Exploitation · 2026-03-09: 1Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-03-22: 1Active Exploitation · 2026-03-27: 1Active Exploitation · 2026-04-11: 1Active Exploitation · 2026-04-16: 1Active Exploitation · 2026-04-27: 2Active Exploitation · 2026-04-28: 5Active Exploitation · 2026-04-29: 1Active Exploitation · 2026-05-04: 2Active Exploitation · 2026-05-06: 1Active Exploitation · 2026-05-07: 1Active Exploitation · 2026-05-13: 2Active Exploitation · 2026-05-25: 1Active Exploitation · 2026-05-27: 2Active Exploitation · 2026-05-30: 1Active Exploitation · 2026-06-15: 4Patch / Workaround · 2026-02-10: 2Patch / Workaround · 2026-02-11: 10Patch / Workaround · 2026-02-12: 11Patch / Workaround · 2026-02-13: 2Patch / Workaround · 2026-02-15: 1Patch / Workaround · 2026-02-16: 3Patch / Workaround · 2026-02-17: 3Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-02-23: 1Patch / Workaround · 2026-03-02: 1Patch / Workaround · 2026-03-04: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-04-16: 1Patch / Workaround · 2026-04-27: 2Patch / Workaround · 2026-04-28: 5Patch / Workaround · 2026-04-29: 1Patch / Workaround · 2026-05-04: 2Patch / Workaround · 2026-05-13: 3Patch / Workaround · 2026-05-24: 1Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-05-30: 1Patch / Workaround · 2026-06-15: 1Patch / Workaround · 2026-07-14: 1Technical Details · 2026-02-10: 3Technical Details · 2026-02-11: 14Technical Details · 2026-02-12: 9Technical Details · 2026-02-13: 4Technical Details · 2026-02-14: 1Technical Details · 2026-02-15: 1Technical Details · 2026-02-16: 3Technical Details · 2026-02-17: 1Technical Details · 2026-02-23: 1Technical Details · 2026-02-27: 1Technical Details · 2026-03-02: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-22: 1Technical Details · 2026-03-27: 1Technical Details · 2026-04-11: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-27: 3Technical Details · 2026-04-28: 8Technical Details · 2026-04-29: 1Technical Details · 2026-05-04: 2Technical Details · 2026-05-06: 1Technical Details · 2026-05-13: 2Technical Details · 2026-05-24: 1Technical Details · 2026-05-25: 1Technical Details · 2026-05-27: 3Technical Details · 2026-05-30: 2Technical Details · 2026-06-13: 2Technical Details · 2026-06-15: 3Technical Details · 2026-07-14: 102-1002-1302-1602-1902-2503-0403-1104-1104-2705-0405-1305-2506-1307-14
Signal classification6 categories
Active Exploitation
5146.8%
Patch
3128.4%
Disclosure
1211.0%
General
1110.1%
Exploit
32.8%
PoC
10.9%
Referenced assets91 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-107
Active Exploitation2Disclosure4Patch1
2026-02-1117
Active Exploitation10Disclosure1Exploit1General2Patch3
2026-02-1216
Active Exploitation5Disclosure2General3Patch6
2026-02-135
Active Exploitation3Disclosure1Patch1
2026-02-141
Active Exploitation1
2026-02-151
Patch1
2026-02-164
Active Exploitation2Patch2
2026-02-173
Active Exploitation1Patch2
2026-02-181
Patch1
2026-02-191
Patch1
2026-02-201
Patch1
2026-02-231
Patch1
2026-02-251
General1
2026-02-271
Disclosure1
2026-03-021
Active Exploitation1
2026-03-041
Patch1
2026-03-091
Active Exploitation1
2026-03-101
Patch1
2026-03-111
Patch1
2026-03-221
Active Exploitation1
2026-03-271
Active Exploitation1
2026-04-111
Active Exploitation1
2026-04-141
Patch1
2026-04-161
Active Exploitation1
2026-04-273
Active Exploitation1Patch2
2026-04-288
Active Exploitation5Disclosure1General1Patch1
2026-04-292
Active Exploitation1Patch1
2026-05-042
Active Exploitation2
2026-05-061
Active Exploitation1
2026-05-072
Active Exploitation1General1
2026-05-133
Active Exploitation2Patch1
2026-05-141
General1
2026-05-241
Patch1
2026-05-251
Active Exploitation1
2026-05-275
Active Exploitation2Exploit2General1
2026-05-302
Active Exploitation1Disclosure1
2026-06-132
Disclosure1General1
2026-06-155
Active Exploitation4Patch1
2026-07-141
PoC1
Full discourse20 posts
  • blackorbird@blackorbird
    Patch

    The second vulnerability (CVE-2026-21510) bypasses security features such as the Microsoft Defender SmartScreen and executes attacker-controlled code, which is stored on the attacker's remote server. An incomplete patch for CVE-2026-21510 (an #APT28 exploit) created a new zero-click vulnerability: CVE-2026-32202. https://www.akamai.com/blog/security-research/2026/apr/incomplete-patch-apt28s-zero-day-cve-2026-32202

    Post summary

    The post highlights a new zero‑click vulnerability (CVE‑2026‑32202) caused by an incomplete patch for CVE‑2026‑21510, noting its ability to bypass Microsoft Defender SmartScreen and execute attacker code, but no PoC or active exploitation is referenced.

    151017010320.4K
    42.7K followersView on X
  • Haifei Li@HaifeiLi
    Patch

    It seems to me that Microsoft just issued additional 3 patches to address the weaknesses in the original Office CVE-2026-21509/zero-day exploit chain. Microsoft Word Security Feature Bypass Vulnerability (CVE-2026-21514) https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21514 Windows Shell Security Feature Bypass Vulnerability (CVE-2026-21510) https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21510 MSHTML Framework Security Feature Bypass Vulnerability (CVE-2026-21513) https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21513 Microsoft Office Security Feature Bypass Vulnerability (CVE-2026-21509) - the original one https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509

    Post summary

    Microsoft released three new patches to address additional weaknesses in the Office zero‑day exploit chain linked to CVE‑2026‑21509 and related CVEs. The advisories note security‑feature bypass vulnerabilities but do not provide PoC, exploit code, or details of active exploitation beyond the implication of a known exploit chain.

    18033114.0K
    8.3K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CISA has added 6 vulnerabilities to the KEV Catalog CVE-2026-21513: Microsoft Internet Explorer Protection Mechanism Failure Vulnerability: Microsoft Internet Explorer contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. CVE-2026-21525: Microsoft Windows NULL Pointer Dereference Vulnerability: Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally. CVE-2026-21510: Microsoft Windows Shell Protection Mechanism Failure Vulnerability: Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. CVE-2026-21533: Microsoft Windows Improper Privilege Management Vulnerability: Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally. CVE-2026-21519: Microsoft Windows Type Confusion Vulnerability: Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally. CVE-2026-21514: Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability: Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally.

    Post summary

    CISA announced six CVEs in the KEV catalog, outlining each vulnerability’s nature and potential impact but providing no PoC, exploit, active exploitation evidence, or patch information.

    09124104.8K
    164.8K followersView on X
  • Horizon Secured@horizon_secured
    Active Exploitation

    🚨 𝗛𝗼𝗿𝗶𝘇𝗼𝗻 𝗔𝗹𝗲𝗿𝘁 – 𝗙𝗲𝗯𝗿𝘂𝗮𝗿𝘆 𝟮𝟬𝟮𝟲 𝗣𝗮𝘁𝗰𝗵 𝗧𝘂𝗲𝘀𝗱𝗮𝘆 February brings 𝟲 𝗮𝗰𝘁𝗶𝘃𝗲𝗹𝘆 𝗲𝘅𝗽𝗹𝗼𝗶𝘁𝗲𝗱 𝘇𝗲𝗿𝗼-𝗱𝗮𝘆𝘀, primarily focused on security feature bypass and privilege escalation. 𝗧𝗿𝗮𝗰𝗸𝗲𝗱 𝗖𝗩𝗘𝘀: 🔸 CVE-2026-21514 🔸 CVE-2026-21510 🔸 CVE-2026-21513 🔸 CVE-2026-21525 🔸 CVE-2026-21533 🔸 CVE-2026-21519 Multiple SYSTEM-level 𝗲𝗹𝗲𝘃𝗮𝘁𝗶𝗼𝗻-𝗼𝗳-𝗽𝗿𝗶𝘃𝗶𝗹𝗲𝗴𝗲 issues and 𝘂𝘀𝗲𝗿-𝗶𝗻𝘁𝗲𝗿𝗮𝗰𝘁𝗶𝗼𝗻 𝗱𝗼𝗰𝘂𝗺𝗲𝗻𝘁 𝗮𝘁𝘁𝗮𝗰𝗸𝘀 are already being exploited in the wild — making endpoint patch prioritization critical. 𝗙𝘂𝗹𝗹 𝗯𝗿𝗲𝗮𝗸𝗱𝗼𝘄𝗻 and insights available in this month’s 𝗛𝗼𝗿𝗶𝘇𝗼𝗻 𝗔𝗹𝗲𝗿𝘁: 🔗 https://horizon-secured.com/newsletter/ #HorizonAlert #Cybersecurity #PatchTuesday #ZeroDay

    Post summary

    February’s Horizon Alert reports six CVEs that are actively exploited in the wild, focusing on privilege escalation and user‑interaction attacks, and stresses the need for immediate patch prioritization.

    020931.1K
    2.2K followersView on X
  • 阿绎 AYi@AYi_AInotes
    Active Exploitation

    Theo 这张清单刷屏了,近期的安全事件如下: CopyFail(Linux 系统被破解) CopyFail 2/Dirty Frag(Linux 内核脏碎片漏洞) Next.js 框架出现 13 个安全警告 MacOS 26.5 系统修复了 70 多个通用漏洞披露(CVE)漏洞 iOS 26.5 系统修复了约 50 个通用漏洞披露(CVE)漏洞 YellowKey(Windows Bitlocker 全盘加密被破解) GreenPlasma(Windows 权限提升漏洞) CVE-2026-21510 和 CVE-2026-21513 被证实由俄罗斯用于 Windows 远程代码执行漏洞攻击 CVE-2026-32202 被单独证实由俄罗斯用于获取敏感文档 Mini-Shai Hulud(超过 300 个 JS 和 Python 软件包因 GitHub Action 缓存投毒而被入侵) 谷歌证实,他们发现了利用人工智能对某个未知的 “开源、基于 Web 的系统管理工具” 进行零日漏洞攻击的情况 Canvas(大多数学校使用的流行学习管理系统)被完全破解 PAN-OS( Palo Alto Networks 公司的操作系统)因严重等级为 9.3 的 CVE-2026-0300 漏洞被破解 我连着看了三天相关报告,越看越觉得这不是个危言耸听的恐怖故事, 更像是软件工程进入后AI安全时代的入学通知。 最关键的信号藏在 CopyFail 里: 一个 732 字节的 Python 脚本, 确定性拿下 2017 年后几乎所有 Linux 发行版的 root。 这玩意竟然是 AI 辅助发现的。 Google 也在同一周确认,AI 驱动的零日已经在野利用了, 俄罗斯 APT 直接武器化两个 Windows CVE, Mini-Shai Hulud 一次劫持 300+ 个 JS/Python 包。 以前一个漏洞躺三年才被人发现, 现在 AI 扫描+AI 利用,未知→已知→武器化几乎同步发生。 更狠的是供应链, Mini-Shai Hulud 告诉所有人一件事: 你信任的 CI/CD 才是最大的后门。 你以为用官方 GitHub Action 就安全, 其实是把 OIDC token 的钥匙拱手送给攻击者。 Perry Metzger 说过一句我反复琢磨的话: bug 的总量是有限的,AI 正在快速耗尽低挂果实。 也就是说,以前安全是"被动 patch", 现在开始转向"AI 实时免疫"。 未来不再是人盯人,会变成 AI 盯 AI。 所以 Theo 问 Are you scared yet, 我的答案是不怕,但必须立刻行动。 第一步不是全站 patch,是把供应链审计提到 P0, GH Actions 全审一遍,禁用 pull_request_target, 强制 SLSA Level 3,启用 SBOM。 那些把"安全作为第一原则"写进 DNA 的团队, 接下来 3-5 年会活得最舒服, 其他人要交的学费,可能比想象中贵得多~

    Post summary

    The post reports that AI‑assisted PoCs are being weaponized and that several high‑impact CVEs are actively exploited in the wild, underscoring urgent patching and supply‑chain defenses.

    700331.1K
    44.0K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(2/10追加) 🛡️No.1509 CVE-2026-21510 Microsoft Windows Shell Protection Mechanism Failure Vulnerability ============= CVSSスコア: 8.8 (Base) / Microsoft Corporation CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:保護メカニズムの不具合 (CWE-693 / Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、悪意のあるリンクやショートカットファイルを介して、リモートよりWindows SmartScreen および Windows Shell のセキュリティプロンプトをバイパスされる恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21510 🛡️No.1510 CVE-2026-21513 Microsoft MSHTML Framework Security Feature Bypass Vulnerability ============= CVSSスコア: 8.8 (Base) / Microsoft Corporation CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:保護メカニズムの不具合 (CWE-693 / Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、細工されたHTMLファイルやショートかっとファイルを介して、リモートから、セキュリティ機能をバイパスされる恐れがあります。 https://msrc.microsoft.com/update-guide/advisory/CVE-2026-21513 🛡️No.1511 CVE-2026-21514 Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability ============= CVSSスコア: 7.8 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:セキュリティ決定の信頼できない入力への依存 (CWE-807/ Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 認証済みの攻撃者により、Officeファイルを介してローカル上でSYSTEM権限を取得される恐れがります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21514 🛡️No.1512 CVE-2026-21519 Microsoft Windows Type Confusion Vulnerability ============= CVSSスコア: 7.8 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 種別:型の取り違え (CWE-843/ Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 認証済みの攻撃者により、ローカル上でSYSTEM権限を取得される恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21519 🛡️No.1513 CVE-2026-21525 Microsoft Windows NULL Pointer Dereference Vulnerability ============= CVSSスコア: 6.2 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 種別:NULL ポインタデリファレンス (CWE-476 / Microsoft Corporation) 深刻度:注意 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、ローカル上でDoSを発生させられる恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21525 🛡️No.1514 CVE-2026-21533 Windows Remote Desktop Services Elevation of Privilege Vulnerability ============= CVSSスコア: 7.8 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 種別:不適切な権限管理 (CWE-269 / Microsoft Corporation) 深刻度:深刻🔥 ---------------------- 悪用時影響: 認証済みの攻撃者により、ローカル上でSYSTEM権限を取得される恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21533 CISA Adds Six Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/02/10/cisa-adds-six-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA added six CVEs confirmed to be exploited in the wild, providing technical details and advisory links, but no PoC, exploit code, or patch information is disclosed in the text.

    000834.7K
    42.5K followersView on X
  • 0patch@0patch
    Patch

    Micropatches released for Windows Shell Security Feature Bypass Vulnerability (CVE-2026-21510) https://blog.0patch.com/2026/04/micropatches-released-for-windows-shell.html https://t.co/hp1PpYcgBB

    Post summary

    The post announces that micropatches have been released to address CVE-2026-21510, indicating a vendor advisory with available remediation.

    04060646
    8.4K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Microsoft ❗ CVE-2026-24300 ❗ CVE-2026-21510 ❗ CVE-2026-20841 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-microsoft-5/ https://t.co/hlwmGgx7eh

    Post summary

    The tweet lists three Microsoft CVEs and directs readers to external links for more information, but it does not provide any technical, exploit, or mitigation details.

    10043274
    6.6K followersView on X
  • Alice Sn0w •ᴗ•@Sn0wAlice
    Active Exploitation

    🔥 Recap cybersec de la semaine (9-15 fév) : 🚨 Patch urgents : • Microsoft : 6 zero-days exploités (CVE-2026-21510/13/14) • Apple : CVE-2026-20700 exploitée en conditions réelles • CISA ajoute 10 vulnérabilités au catalogue KEV • BeyondTrust CVE-2026-1731 : RCE critique non authentifiée 💥 Incidents majeurs : • Conduent : 25M d'Américains affectés (données Medicaid) • Telegram : +200M d'enregistrements exposés • Harvard : 115K dossiers compromis (ShinyHunters) 🤖 Menaces IA : • Assistants de codage IA copient du code vers la Chine • LLM de plus en plus efficaces pour exploiter les vulns • +300 extensions Chrome malveillantes (37M téléchargements) 🔓 Supply chain : • Notepad++ backdoorisé + compromis par APT chinois • Microsoft donne les clés BitLocker au FBI #cybersecurity #infosec #zerodayupdates

    Post summary

    The report highlights multiple zero-day vulnerabilities actively exploited in the wild, prompting urgent patching across major vendors such as Microsoft and Apple.

    11050484
    1.6K followersView on X
  • Brian in Pittsburgh@arekfurt
    Disclosure

    Hmm. This was a pretty nice 0day for some group. (As far as vulns requiring users to click on files go, anyway.) Results in LNK attacks being turbocharged by bypass of even execution prompts/warnings. (Already too easy to fool users into clicking LNKs.) https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21510 https://t.co/dIvb33ZSAC

    Post summary

    The tweet references the newly disclosed Windows LNK bypass vulnerability CVE‑2026‑21510, noting its impact on bypassing execution prompts, but does not provide exploit code, patches, or evidence of active exploitation.

    021311.6K
    6.9K followersView on X
  • dbugs@ptdbugs
    PoC

    CVE-2026-32202: The Trust Check Runs at the Click. The Coercion Runs at the Icon PT ID: PT-2026-32854 Akamai researchers analyzed the Windows Shell vulnerability CVE-2026-32202 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-32202), which resulted from an incomplete fix for the previously exploited CVE-2026-21510 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-21510). In February 2026, Microsoft patched the remote code execution vector by enforcing SmartScreen trust verification before executing Control Panel applets, but one issue went unnoticed: Explorer still automatically connects to an attacker’s SMB server when displaying a folder’s contents. The Microsoft patch moved the trust verification ("ControlPanelLinkSite", "IVerifyingTrust::OnVerifyingTrust") only to the execution stage via "ShellExecuteExW", but didn’t fix the execution path during enumeration, tooltip display, or preview. Because of a bug in "shell32.dll", the "_IDCONTROLW" structure for Control Panel items ("Control Panel applet") can trigger a call to "PathFileExistsW" by viewing a folder containing a ".lnk" file. This causes Explorer to initiate an SMB connection and leak the NTLMv2 hash before any user interaction and regardless of SmartScreen. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-32854 • https://nefariousplan.com/posts/cve-2026-32202-trust-check-at-the-click • https://github.com/virus-or-not/CVE-2026-32202 #dbugs_attacks

    Post summary

    The post announces CVE-2026-32202, detailing how an incomplete Microsoft patch allows SMB hash leakage via Control Panel items, includes a GitHub PoC, and notes the patch applied in February 2026.

    00042464
    3.4K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Active Exploitation

    ⚙️ القصة من البداية: في ديسمبر 2025، استهدفت (APT28) أجهزة ويندوز بملف اختصار خبيث. لما يقرأه الويندوز، يحسبه جزء من لوحة التحكم (Control Panel) ويشغّل ملف (DLL) من سيرفر المخترق مايكروسوفت قفلت الثغرة (CVE-2026-21510) في فبراير 2026.. بس الترقيع كان ناقص وتسبب بثغره ثانيه ! 2/5 https://t.co/mL5mViYzZt

    Post summary

    APT28 actively exploited CVE-2026-21510 via malicious shortcuts, and Microsoft released a patch in February 2026, though the fix was incomplete.

    10041983
    49.3K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    CISA mandates federal agencies to patch a Windows zero-click vulnerability CVE-2026-32202 by May 12 under BOD 22-01. The flaw connects to APT28 and follows an incomplete Microsoft fix for CVE-2026-21510. #CVE2026 #APT28 #USA https://ift.tt/4mC6vhx

    Post summary

    CISA mandates a patch for CVE‑2026‑32202, a Windows zero‑click flaw linked to APT28, with no evidence of active exploitation or PoC provided.

    00041193
    4.4K followersView on X
  • Pixelco Tech@PixelcoTech
    Patch

    Destaca la brecha crítica CVE-2026-21510, que permite evadir las alertas de seguridad de Windows Shell. Se requiere el despliegue inmediato de parches en todos los clientes de red (MSRC/Rapid7).

    Post summary

    CVE-2026-21510 es una brecha crítica que permite evadir las alertas de seguridad de Windows Shell, y se requiere el despliegue inmediato de parches en todos los clientes de red.

    00041199
    6.8K followersView on X
  • Chukwuemeka@chukwuemekaoa
    Active Exploitation

    5 breaches making headlines: 1. Warlock ransomware hit SmarterTools via unpatched SmarterMail (CVE-2026-23760) 2. China-linked UNC3886 targeting Singapore telecom with zero-days 3. Microsoft Windows Shell zero-day (CVE-2026-21510) actively exploited databreach. 1/2

    Post summary

    CVE-2026-21510 is actively exploited in a Windows Shell zero‑day attack, while CVE-2026-23760 remains unpatched with no mention of mitigation or PoC.

    11020186
    344 followersView on X
  • Shahzad Khalid  @ShahzadKhld
    Active Exploitation

    Microsoft recently updated its advisory for CVE-2026-32202, confirming that this Windows Shell flaw is now being actively exploited in the wild. While originally labeled as a "spoofing" vulnerability with a lower severity score, new research has revealed it is a critical link in an exploit chain used by nation-state actors. Technical Overview: CVE-2026-32202 is an authentication coercion vulnerability. It stems from an "incomplete patch" for a previous flaw (CVE-2026-21510) that was weaponized by the Russian threat group APT28 (also known as Fancy Bear). 1- The Mechanism: The flaw exists in how the Windows Shell parses namespace objects, specifically Control Panel (.CPL) files. 2- The Attack: An attacker can craft a malicious shortcut file (.LNK) or a web link that points to a remote server using a UNC path (e.g., \\attacker-server\share\payload.cpl). 3- The Flaw: When Windows Shell attempts to resolve this path to display the file's icon or properties, it automatically initiates an SMB connection. 4- The Consequence: This triggers an automatic NTLM authentication handshake. The victim's machine sends its Net-NTLMv2 hash to the attacker’s server without any user interaction (Zero-Click). Why It’s Dangerous: While the vulnerability itself is rated CVSS 4.3 (Medium) because it only "discloses information," its role in real-world attacks is far more severe: 1- Credential Theft: Attackers capture your NTLM hashes to crack them offline or use them in NTLM Relay attacks to impersonate you on other parts of the network. 2- Zero-Click Vector: In certain scenarios (like viewing a folder containing a malicious .LNK file), the exploitation happens automatically as Windows tries to "preview" the file. 3- Nation-State Activity: Its active use by APT28 suggests it is being used for high-value espionage and lateral movement within corporate and government networks. Affected Systems: The flaw affects nearly all modern versions of Windows, including: 1- Windows 10 & 11 (all recent versions, including 24H2 and 26H1). 2- Windows Server (2012 through 2025). Mitigation and Action Plan: Microsoft released a patch for this as part of the April 2026 Patch Tuesday updates. If you haven't updated since mid-April, your system is likely vulnerable.

    Post summary

    Microsoft confirmed CVE-2026-32202 is being actively exploited by nation-state actors, with a dedicated patch released; the vulnerability involves NTLM hash theft via zero‑click Windows Shell attacks.

    0111079
    421 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE-2026-21510: Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.

    Post summary

    The statement briefly identifies a protection mechanism failure in Microsoft Windows Shell, but it does not provide any evidence of exploitation, PoC, or remediation.

    1001046
    183 followersView on X
  • VulnTracker@vuln_tracker
    General

    @the_yellow_fall Fancy Bear. zero-click. NTLM theft. original patch wasn't enough. this is the same class of bug as CVE-2026-21510 - Windows Shell keeps handing APT28 new keys. how many times do we patch the same mistake? http://vulntracker.io

    Post summary

    The tweet references CVE‑2026‑21510, noting a zero‑click NTLM theft and that the original patch was insufficient, but it offers no PoC, exploit code, or active exploitation report.

    01010150
    581 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    An incomplete Windows patch for SmartScreen and Shell prompts enabled zero-click attacks using malicious LNK and HTML files, exploited by Russia-linked APT28 via CVE-2026-21513 and CVE-2026-21510. #APT28 #WindowsPatch #Russia https://ift.tt/skQF4nJ

    Post summary

    CVE‑2026‑21513 and CVE‑2026‑21510 are being actively exploited in zero‑click attacks via malicious .lnk and .html files by APT28, demonstrating real‑world use of these vulnerabilities.

    01001151
    4.1K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2026-21510 allowed malicious Windows shortcuts to execute remote DLLs without security warnings, bypassing mark-of-the-web protections. 0patch releases micropatches for legacy Windows systems after wild exploitation confirmed. #DFIR_Radar https://t.co/eJkqChik9X

    Post summary

    CVE‑2026‑21510 allows malicious Windows shortcuts to load remote DLLs, bypassing security warnings; the vulnerability is being exploited in the wild and 0patch has issued micropatches for legacy Windows systems.

    10010128
    1.7K followersView on X
CPE platform detail23 entries

23 of 23 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more