CVE-2026-21514Active Exploitation(microsoft / 365_apps)

CRITICALCVSS 7.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 15 mentions and remains active

Immediate actions

  • Patch microsoft 365_apps systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-03. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-807

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_apps
  • office_long_term_servicing_channel

Threat summary

  • Active exploitation appears in 36 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 67 mentions across 22 observed days

What's happening

  • Active exploitation reported across 36 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 20 signals
  • Technical details provided in 40 signals
  • General: 15 classified signals
  • Disclosure: 11 classified signals
  • Peaked 20d ago at 15 mentions (2026-02-11); latest day: 1
  • 67 total mentions across 22 days

Affected systems

Vendors
Products
365_appsoffice_long_term_servicing_channel

3 versions affected across 2 products

Deep dive

Activity timeline67 mentions / 22d
0481115Mentions · 2026-02-10: 6Mentions · 2026-02-11: 15Mentions · 2026-02-12: 8Mentions · 2026-02-13: 3Mentions · 2026-02-16: 2Mentions · 2026-02-17: 2Mentions · 2026-02-18: 1Mentions · 2026-02-20: 1Mentions · 2026-03-03: 1Mentions · 2026-03-05: 1Mentions · 2026-03-10: 1Mentions · 2026-03-18: 5Mentions · 2026-03-19: 4Mentions · 2026-03-20: 3Mentions · 2026-03-22: 1Mentions · 2026-03-27: 2Mentions · 2026-03-31: 1Mentions · 2026-04-15: 5Mentions · 2026-05-07: 2Mentions · 2026-05-08: 1Mentions · 2026-05-11: 1Mentions · 2026-05-17: 1PoC Mentioned / Linked · 2026-03-27: 1PoC Mentioned / Linked · 2026-05-07: 1Exploit Tool / Code · 2026-05-07: 1Active Exploitation · 2026-02-10: 2Active Exploitation · 2026-02-11: 11Active Exploitation · 2026-02-12: 6Active Exploitation · 2026-02-13: 1Active Exploitation · 2026-02-16: 2Active Exploitation · 2026-02-17: 1Active Exploitation · 2026-02-18: 1Active Exploitation · 2026-03-03: 1Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-03-18: 2Active Exploitation · 2026-03-19: 2Active Exploitation · 2026-03-20: 1Active Exploitation · 2026-03-22: 1Active Exploitation · 2026-05-07: 2Active Exploitation · 2026-05-08: 1Active Exploitation · 2026-05-17: 1Patch / Workaround · 2026-02-10: 2Patch / Workaround · 2026-02-11: 6Patch / Workaround · 2026-02-12: 3Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-16: 1Patch / Workaround · 2026-02-17: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-19: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-04-15: 2Patch / Workaround · 2026-05-07: 1Technical Details · 2026-02-10: 3Technical Details · 2026-02-11: 11Technical Details · 2026-02-12: 3Technical Details · 2026-02-13: 3Technical Details · 2026-02-17: 2Technical Details · 2026-02-20: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-18: 2Technical Details · 2026-03-19: 3Technical Details · 2026-03-20: 3Technical Details · 2026-03-22: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-15: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-17: 102-1002-1202-1602-1803-0303-1003-1903-2203-3105-0705-1105-17
Signal classification5 categories
Active Exploitation
3146.3%
General
1522.4%
Disclosure
1116.4%
Patch
913.4%
PoC
11.5%
Referenced assets51 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-106
Active Exploitation1Disclosure3Patch2
2026-02-1115
Active Exploitation10Disclosure3General1Patch1
2026-02-128
Active Exploitation6General2
2026-02-133
Active Exploitation1Disclosure1General1
2026-02-162
Active Exploitation1Patch1
2026-02-172
Active Exploitation1Disclosure1
2026-02-181
Active Exploitation1
2026-02-201
Disclosure1
2026-03-031
Active Exploitation1
2026-03-051
Disclosure1
2026-03-101
Patch1
2026-03-185
Active Exploitation1Disclosure1General3
2026-03-194
Active Exploitation2General1Patch1
2026-03-203
Active Exploitation1General1Patch1
2026-03-221
Active Exploitation1
2026-03-272
General1PoC1
2026-03-311
General1
2026-04-155
General3Patch2
2026-05-072
Active Exploitation2
2026-05-081
Active Exploitation1
2026-05-111
General1
2026-05-171
Active Exploitation1
Full discourse20 posts
  • Cyber Security News@The_Cyber_News
    Active Exploitation

    🚨 Microsoft Office Word 0-day Vulnerability Actively Exploited in the Wild Source: https://cybersecuritynews.com/microsoft-office-word-0-day-vulnerability/ A critical zero-day vulnerability in Microsoft Word, tracked as CVE-2026-21514, was disclosed on February 10, 2026, allowing attackers to bypass essential security protections. CVE-2026-21514 exploits a weakness in how Microsoft Word handles security decisions based on untrusted inputs, categorized as CWE-807. The vulnerability specifically bypasses Object Linking and Embedding (OLE) mitigations implemented by Microsoft to protect users from malicious COM/OLE controls. These OLE controls enable documents to embed and interact with external objects. However, improper validation allows attackers to circumvent protective measures. #cybersecuritynews #vulnerability

    Post summary

    CVE-2026-21514 is a critical zero‑day in Microsoft Word that bypasses OLE mitigations and is actively exploited in the wild, with no publicly disclosed patch or PoC provided.

    7129936715823.3K
    48.0K followersView on X
  • Haifei Li@HaifeiLi
    Patch

    It seems to me that Microsoft just issued additional 3 patches to address the weaknesses in the original Office CVE-2026-21509/zero-day exploit chain. Microsoft Word Security Feature Bypass Vulnerability (CVE-2026-21514) https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21514 Windows Shell Security Feature Bypass Vulnerability (CVE-2026-21510) https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21510 MSHTML Framework Security Feature Bypass Vulnerability (CVE-2026-21513) https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21513 Microsoft Office Security Feature Bypass Vulnerability (CVE-2026-21509) - the original one https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509

    Post summary

    Microsoft released patches for several Office and Windows feature‑bypass vulnerabilities (CVE‑2026‑21509 through CVE‑2026‑21514), addressing weaknesses identified in the original zero‑day exploit chain.

    18033114.0K
    8.3K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CISA has added 6 vulnerabilities to the KEV Catalog CVE-2026-21513: Microsoft Internet Explorer Protection Mechanism Failure Vulnerability: Microsoft Internet Explorer contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. CVE-2026-21525: Microsoft Windows NULL Pointer Dereference Vulnerability: Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally. CVE-2026-21510: Microsoft Windows Shell Protection Mechanism Failure Vulnerability: Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. CVE-2026-21533: Microsoft Windows Improper Privilege Management Vulnerability: Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally. CVE-2026-21519: Microsoft Windows Type Confusion Vulnerability: Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally. CVE-2026-21514: Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability: Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally.

    Post summary

    CISA has added six Microsoft CVEs to the KEV catalog, outlining protection failures and privilege‑escalation scenarios, but no exploit details, patches, or active exploitation information are provided.

    09124104.8K
    164.8K followersView on X
  • Cyber_OSINT@Cyber_O51NT
    Disclosure

    Tenable found that a Word N-day (CVE-2026-21514) exposed nearly 14 million assets across seven countries, dwarfing headline threats and shaping a hybrid, US-heavy risk surface that will persist beyond any ceasefire. https://www.tenable.com/blog/operation-epic-fury-why-exposure-data-changes-everything-about-irans-cyber-kinetic-campaign

    Post summary

    The blog post announces that Tenable discovered CVE‑2026‑21514, exposing about 14 million assets, but it does not provide proof‑of‑concept, exploit, or remediation details.

    050102776
    21.6K followersView on X
  • Horizon Secured@horizon_secured
    Active Exploitation

    🚨 𝗛𝗼𝗿𝗶𝘇𝗼𝗻 𝗔𝗹𝗲𝗿𝘁 – 𝗙𝗲𝗯𝗿𝘂𝗮𝗿𝘆 𝟮𝟬𝟮𝟲 𝗣𝗮𝘁𝗰𝗵 𝗧𝘂𝗲𝘀𝗱𝗮𝘆 February brings 𝟲 𝗮𝗰𝘁𝗶𝘃𝗲𝗹𝘆 𝗲𝘅𝗽𝗹𝗼𝗶𝘁𝗲𝗱 𝘇𝗲𝗿𝗼-𝗱𝗮𝘆𝘀, primarily focused on security feature bypass and privilege escalation. 𝗧𝗿𝗮𝗰𝗸𝗲𝗱 𝗖𝗩𝗘𝘀: 🔸 CVE-2026-21514 🔸 CVE-2026-21510 🔸 CVE-2026-21513 🔸 CVE-2026-21525 🔸 CVE-2026-21533 🔸 CVE-2026-21519 Multiple SYSTEM-level 𝗲𝗹𝗲𝘃𝗮𝘁𝗶𝗼𝗻-𝗼𝗳-𝗽𝗿𝗶𝘃𝗶𝗹𝗲𝗴𝗲 issues and 𝘂𝘀𝗲𝗿-𝗶𝗻𝘁𝗲𝗿𝗮𝗰𝘁𝗶𝗼𝗻 𝗱𝗼𝗰𝘂𝗺𝗲𝗻𝘁 𝗮𝘁𝘁𝗮𝗰𝗸𝘀 are already being exploited in the wild — making endpoint patch prioritization critical. 𝗙𝘂𝗹𝗹 𝗯𝗿𝗲𝗮𝗸𝗱𝗼𝘄𝗻 and insights available in this month’s 𝗛𝗼𝗿𝗶𝘇𝗼𝗻 𝗔𝗹𝗲𝗿𝘁: 🔗 https://horizon-secured.com/newsletter/ #HorizonAlert #Cybersecurity #PatchTuesday #ZeroDay

    Post summary

    The Horizon Alert highlights six CVEs that are actively exploited for privilege escalation, underscoring the urgency of patching though no detailed mitigations or PoC are provided.

    020931.1K
    2.2K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(2/10追加) 🛡️No.1509 CVE-2026-21510 Microsoft Windows Shell Protection Mechanism Failure Vulnerability ============= CVSSスコア: 8.8 (Base) / Microsoft Corporation CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:保護メカニズムの不具合 (CWE-693 / Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、悪意のあるリンクやショートカットファイルを介して、リモートよりWindows SmartScreen および Windows Shell のセキュリティプロンプトをバイパスされる恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21510 🛡️No.1510 CVE-2026-21513 Microsoft MSHTML Framework Security Feature Bypass Vulnerability ============= CVSSスコア: 8.8 (Base) / Microsoft Corporation CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:保護メカニズムの不具合 (CWE-693 / Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、細工されたHTMLファイルやショートかっとファイルを介して、リモートから、セキュリティ機能をバイパスされる恐れがあります。 https://msrc.microsoft.com/update-guide/advisory/CVE-2026-21513 🛡️No.1511 CVE-2026-21514 Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability ============= CVSSスコア: 7.8 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:セキュリティ決定の信頼できない入力への依存 (CWE-807/ Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 認証済みの攻撃者により、Officeファイルを介してローカル上でSYSTEM権限を取得される恐れがります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21514 🛡️No.1512 CVE-2026-21519 Microsoft Windows Type Confusion Vulnerability ============= CVSSスコア: 7.8 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 種別:型の取り違え (CWE-843/ Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 認証済みの攻撃者により、ローカル上でSYSTEM権限を取得される恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21519 🛡️No.1513 CVE-2026-21525 Microsoft Windows NULL Pointer Dereference Vulnerability ============= CVSSスコア: 6.2 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 種別:NULL ポインタデリファレンス (CWE-476 / Microsoft Corporation) 深刻度:注意 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、ローカル上でDoSを発生させられる恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21525 🛡️No.1514 CVE-2026-21533 Windows Remote Desktop Services Elevation of Privilege Vulnerability ============= CVSSスコア: 7.8 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 種別:不適切な権限管理 (CWE-269 / Microsoft Corporation) 深刻度:深刻🔥 ---------------------- 悪用時影響: 認証済みの攻撃者により、ローカル上でSYSTEM権限を取得される恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21533 CISA Adds Six Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/02/10/cisa-adds-six-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA has confirmed exploitation of six Windows vulnerabilities and added them to the KEV catalog, providing detailed CVSS and impact information for each CVE.

    000834.7K
    42.5K followersView on X
  • ET Labs@ET_Labs
    General

    180 new OPEN, 213 new PRO (180 + 33) Bandwidth Sharing Tools, Passive Income app domains, Lumma stealer, LandUpdate808, ZPHP, Tycoon 2FA, upStage Residential proxy, Microsoft MSHTML Framework (CVE-2026-21513), Microsoft Word (CVE-2026-21514), and more. https://community.emergingthreats.net/t/ruleset-update-summary-2026-02-11-v11123/3194

    Post summary

    The post enumerates newly reported vulnerabilities, including CVE-2026-21513 and CVE-2026-21514, but offers no technical details, exploitation evidence, or mitigation information.

    02120407
    5.7K followersView on X
  • Szabolcs Schmidt@smica83
    PoC

    Another Meteo Ukraine themed DOC as a CVE-2026-21509 and CVE-2026-21514 exploit @abuse_ch https://bazaar.abuse.ch/sample/479fd5e5bd5566a0252acd4ec29c5abc0dac501d0d6e9f316612b52aa48a3587/ Creation date is the 29th of January but the hash is different as in the @_CERT_UA report. First submission was yesterday. @500mk500 https://t.co/daEKLkl3l7

    Post summary

    A sample linked to CVE‑2026‑21509 and CVE‑2026‑21514 suggests a PoC has been released, but no detailed exploitation code or active use evidence is provided.

    01030314
    3.4K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-20841 2 - CVE-2026-23760 3 - CVE-2026-21508 4 - CVE-2024-27834 5 - CVE-2026-21514 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet lists the top 5 trending CVEs without providing any additional details such as PoC, exploit code, patch information, or technical specifics.

    00020190
    1.7K followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISA、6つの既知の脆弱性をカタログに追加 CISA Adds Six Known Exploited Vulnerabilities to Catalog #CISA (Feb 10) CVE-2026-21510 Microsoft Windows シェル保護メカニズムの失敗の脆弱性 CVE-2026-21513 Microsoft MSHTML フレームワークのセキュリティ機能バイパスの脆弱性 CVE-2026-21514 Microsoft Office Word のセキュリティ決定における信頼できない入力への依存の脆弱性 CVE-2026-21519 Microsoft Windows の型混乱の脆弱性 CVE-2026-21525 Microsoft Windows の NULL ポインタ逆参照の脆弱性 CVE-2026-21533 Windows リモート デスクトップ サービスの権限昇格の脆弱性 https://www.cisa.gov/news-events/alerts/2026/02/10/cisa-adds-six-known-exploited-vulnerabilities-catalog

    Post summary

    CISA announced that six Microsoft CVEs have been added to its catalog of known exploited vulnerabilities, signaling active exploitation, but the notice does not provide patches, PoC, or exploit code.

    00011354
    4.7K followersView on X
  • Ajay Prakash@Im_AjayPrakash
    Active Exploitation

    🚨 New Microsoft Word Zero-Day Alert Microsoft just patched CVE-2026-21514, a critical security bypass vulnerability being exploited in the wild! 🛡️

    Post summary

    Microsoft has patched CVE‑2026‑21514, a critical Word vulnerability, which is reportedly being exploited in the wild.

    1100070
    70 followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Active Exploitation

    Microsoft Patch Tuesday security updates for February 2026 fix six actively exploited zero-days https://securityaffairs.com/187848/uncategorized/microsoft-patch-tuesday-security-updates-for-february-2026-fix-six-actively-exploited-zero-days.html "Microsoft labeled CVE-2026-21510, CVE-2026-21514 and CVE-2026-21513 as “publicly disclosed”."

    Post summary

    Microsoft released Patch Tuesday updates for February 2026 that address six actively exploited zero-day vulnerabilities, including CVE‑2026‑21510, CVE‑2026‑21513, and CVE‑2026‑21514.

    10100338
    3.4K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://lyrie.ai/research/research/active-exploit-cve-2026-21514-office #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The linked research article announces that CVE‑2026‑21514 in Microsoft Office is being actively exploited, includes PoC/exploit details, and highlights real-world misuse, with no evidence of a patch or false‑positive claim.

    0001035
    183 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:00 UTC: CVE-2026-21514 disclosed. CISA: CVE-2026-21514 added to Known Exploited Vulnerabilities — Microsoft Office Status: ✅ Confirmed exploited in the wild Date added: 2026-02-10 Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01…

    Post summary

    CVE-2026-21514 is a confirmed actively exploited vulnerability in the wild, with vendors issuing mitigations.

    1000047
    183 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Iran's 🇮🇷 Operation Epic Fury retaliation reveals Microsoft Word CVE-2026-21514 affects 14M assets across 7 countries—247x more exposure than headline IP camera exploits. US 🇺🇸 carries 99. #DFIR_Radar https://t.co/I3OvD24Fys

    Post summary

    Microsoft Word CVE-2026-21514 is reportedly being actively exploited by Iran's Operation Epic Fury, impacting 14 million assets across seven countries, with no PoC, exploit code, or patch details disclosed.

    100006
    38 followersView on X
  • Peter Casano@pcasano
    Active Exploitation

    FAQ on CVE-2026-21514: OLE bypass N-Day in Microsoft Word http://ow.ly/Ec3V106w0Yh https://t.co/LTmCM1HvYT

    Post summary

    The tweet points to an FAQ about CVE‑2026‑21514, an OLE bypass in Microsoft Word that is currently being exploited as an N‑Day vulnerability, but it does not provide a PoC, exploit code, or patch details.

    0001026
    15 followersView on X
  • Vivek | Cybersecurity@VivekIntel
    General

    A Microsoft Word vulnerability (CVE-2026-21514) is emerging as a key attack vector in an Iran-linked hybrid campaign, exposing ~14 million systems across seven countries. Nearly 99.4% of exposure is concentrated in the U.S., highlighting a massive and persistent attack surface even beyond active conflict phases. https://www.tenable.com/blog/operation-epic-fury-why-exposure-data-changes-everything-about-irans-cyber-kinetic-campaign #CyberSecurity #ThreatIntel #Iran #Vulnerability #Exposure

    Post summary

    The post highlights Microsoft Word CVE-2026-21514 as a possible key vector for an Iran-linked campaign, but lacks detail on exploitation, patches, or technical specifics.

    0010091
    295 followersView on X
  • İmam Gazali@boo8ow1923
    Patch

    İşte güncel ve yamasız kritik güvenlik zafiyetlerinin CVE listesi, önem derecesine göre sıralanmış şekilde: ## Kritik Zafiyetler (CVSS 10.0 - En Yüksek Risk) - **Cisco Secure Firewall ürünleri**: Mart 2026 güncellemesinde 48 güvenlik açığı giderildi, bunlardan 2 tanesi CVSS 10.0 seviyesinde kritik açıklardır. Bu açıklar saldırganlara sistem kontrolü vermektedir.^4^ ## Sıfır Gün Açıkları (Aktif İstismar Riski) - **CVE-2026-21385**: Android için - sınırlı ve hedefli istismar edildiğine dair işaretler bulunan sıfır gün açığı^1^ - **CVE-2026-21510**: Windows Shell güvenlik özelliği atlama açığı^3^ - **CVE-2026-21513**: MSHTML Framework güvenlik özelliği atlama açığı^3^ - **CVE-2026-21514**: Microsoft Word güvenlik özelliği atlama açığı^3^ - **CVE-2026-21519**: Desktop Window Manager yetki yükseltme açığı^3^ - **CVE-2026-21533**: Remote Desktop Services yetki yükseltme açığı^3^ - **CVE-2026-21525**: Remote Access Connection Manager hizmet aksatma açığı^3^ ## Google Chrome Kritik Açıkları - **CVE-2026-3536**: ANGLE'da tamsayı taşması (Kritik)^10^ - **CVE-2026-3537**: PowerVR'da nesne yaşam döngüsü sorunu (Kritik)^10^ - **CVE-2026-3538**: Skia'da tamsayı taşması (Kritik)^10^ ## Yüksek Önemli Açıklar - **CVE-2026-3539**: DevTools'da nesne yaşam döngüsü sorunu (Yüksek)^10^ - **CVE-2026-3540**: WebAudio'da uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3541**: CSS'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3542**: WebAssembly'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3543**: V8'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3544**: WebCodecs'da heap buffer overflow (Yüksek)^10^ - **CVE-2026-3545**: Navigasyonda yetersiz veri doğrulama (Yüksek)^10^ ## Güncelleme Önerileri - **Windows 11**: KB5077181 (25H2/24H2) ve KB5075941 (23H2) güncellemeleri ile 6 sıfır gün açığı kapatıldı^3^ - **Android**: 2026-03-05 güvenlik yama seviyesi veya üzeri tüm açıkları giderir^1,2^ - **Google Chrome**: En son sürüme güncelleme yapılması kritik açıklar için zorunludur^1^ - **Cisco ürünleri**: Mart 2026 paket güvenlik güncellemesinin uygulanması gerekir^4^ Bu zafiyetler arasında özellikle sıfır gün açıkları ve CVSS 10.0 seviyesindeki açıklar en yüksek riski taşımaktadır ve acil olarak yamanması gerekmektedir.

    Post summary

    The post catalogs several critical zero‑day CVEs, many with CVSS 10.0, and supplies patch/update instructions for Cisco, Windows, Android, and Chrome, while noting that certain vulnerabilities are already being actively exploited.

    0100071
    48 followersView on X
  • Tim Wilson@TimWilsonAtDxc
    Disclosure

    The third security feature bypass zero-day, CVE-2026-21514 (CVSS 7.8), affects Microsoft Word and once again involves user interaction for a successful exploit https://livesocial.seismic.com/tJUKtj

    Post summary

    The post announces a CVE-2026-21514 security feature bypass zero‑day in Microsoft Word with CVSS 7.8, requiring user interaction, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    00010133
    44 followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    Microsoft 2026-02 月例アップデート:6 件のゼロデイを含む 58 件の脆弱性に対応 https://iototsecnews.jp/2026/02/10/microsoft-february-2026-patch-tuesday-fixes-6-zero-days-58-flaws/ 2026年2月の Microsoft Patch Tuesday における、多数のゼロデイ脆弱性を含む更新プログラムの公開について解説する記事です。今回の更新では、CVE-2026-21510 (Windows Shell)/CVE-2026-21513 (MSHTML)/CVE-2026-21514 (Word) などにおいて、すでに悪用が確認されている 6 件のゼロデイ脆弱性が修正されました。これらは、セキュリティ警告をすり抜け、最高権限 (SYSTEM 権限) を奪取するなどの、きわめて高いリスクを伴うものです。ご利用のチームは、ご注意ください。 #CVE202621510 #CVE202621513 #CVE202621514 #CVE202621519 #CVE202621525 #CVE202621533 #Exploit #Microsoft #PatchTuesday #Vulnerability #ZeroDay

    Post summary

    Microsoft’s February 2026 Patch Tuesday addressed 58 vulnerabilities, including six zero‑days that have already been exploited in the wild, with critical fixes for components like Windows Shell, MSHTML, and Word.

    01000208
    484 followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_apps--x64
Appmicrosoft365_apps--x86
Appmicrosoftoffice_long_term_servicing_channel2021-x64
Appmicrosoftoffice_long_term_servicing_channel2021-x86
Appmicrosoftoffice_long_term_servicing_channel2021macos-
Appmicrosoftoffice_long_term_servicing_channel2024-x64
Appmicrosoftoffice_long_term_servicing_channel2024-x86
Appmicrosoftoffice_long_term_servicing_channel2024macos-

Explore more