CVE-2026-21519Active Exploitation(microsoft / windows_10_1607)

CRITICALCVSS 7.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 11 mentions and remains active

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

8.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-03. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-843

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Active exploitation appears in 21 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 33 mentions across 11 observed days

What's happening

  • Active exploitation reported across 21 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 16 signals
  • Technical details provided in 26 signals
  • Disclosure: 5 classified signals
  • Peaked 9d ago at 11 mentions (2026-02-11); latest day: 2
  • 33 total mentions across 11 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_server_2016windows_server_2019windows_server_2022

Deep dive

Activity timeline33 mentions / 11d
036811Mentions · 2026-02-10: 5Mentions · 2026-02-11: 11Mentions · 2026-02-12: 6Mentions · 2026-02-13: 2Mentions · 2026-02-14: 1Mentions · 2026-02-22: 1Mentions · 2026-03-02: 1Mentions · 2026-03-10: 1Mentions · 2026-03-12: 2Mentions · 2026-03-22: 1Mentions · 2026-05-08: 2PoC Mentioned / Linked · 2026-02-11: 1PoC Mentioned / Linked · 2026-05-08: 1Exploit Tool / Code · 2026-05-08: 1Active Exploitation · 2026-02-10: 2Active Exploitation · 2026-02-11: 8Active Exploitation · 2026-02-12: 3Active Exploitation · 2026-02-13: 1Active Exploitation · 2026-02-14: 1Active Exploitation · 2026-02-22: 1Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-03-12: 1Active Exploitation · 2026-03-22: 1Active Exploitation · 2026-05-08: 2Patch / Workaround · 2026-02-10: 1Patch / Workaround · 2026-02-11: 6Patch / Workaround · 2026-02-12: 4Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-22: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-05-08: 1Technical Details · 2026-02-10: 5Technical Details · 2026-02-11: 10Technical Details · 2026-02-12: 2Technical Details · 2026-02-13: 1Technical Details · 2026-02-14: 1Technical Details · 2026-02-22: 1Technical Details · 2026-03-02: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-12: 2Technical Details · 2026-03-22: 1Technical Details · 2026-05-08: 102-1002-1102-1202-1302-1402-2203-0203-1003-1203-2205-08
Signal classification4 categories
Active Exploitation
1751.5%
Patch
721.2%
Disclosure
515.2%
General
412.1%
Referenced assets24 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-105
Active Exploitation2Disclosure3
2026-02-1111
Active Exploitation8Disclosure2General1
2026-02-126
Active Exploitation1General1Patch4
2026-02-132
Active Exploitation1General1
2026-02-141
Active Exploitation1
2026-02-221
Patch1
2026-03-021
General1
2026-03-101
Patch1
2026-03-122
Active Exploitation1Patch1
2026-03-221
Active Exploitation1
2026-05-082
Active Exploitation2
Full discourse20 posts
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CISA has added 6 vulnerabilities to the KEV Catalog CVE-2026-21513: Microsoft Internet Explorer Protection Mechanism Failure Vulnerability: Microsoft Internet Explorer contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. CVE-2026-21525: Microsoft Windows NULL Pointer Dereference Vulnerability: Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally. CVE-2026-21510: Microsoft Windows Shell Protection Mechanism Failure Vulnerability: Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. CVE-2026-21533: Microsoft Windows Improper Privilege Management Vulnerability: Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally. CVE-2026-21519: Microsoft Windows Type Confusion Vulnerability: Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally. CVE-2026-21514: Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability: Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally.

    Post summary

    CISA announced six Microsoft CVEs added to the KEV catalog, detailing each vulnerability’s type and potential impact on privilege escalation or service denial.

    09124104.8K
    164.8K followersView on X
  • Horizon Secured@horizon_secured
    Active Exploitation

    🚨 𝗛𝗼𝗿𝗶𝘇𝗼𝗻 𝗔𝗹𝗲𝗿𝘁 – 𝗙𝗲𝗯𝗿𝘂𝗮𝗿𝘆 𝟮𝟬𝟮𝟲 𝗣𝗮𝘁𝗰𝗵 𝗧𝘂𝗲𝘀𝗱𝗮𝘆 February brings 𝟲 𝗮𝗰𝘁𝗶𝘃𝗲𝗹𝘆 𝗲𝘅𝗽𝗹𝗼𝗶𝘁𝗲𝗱 𝘇𝗲𝗿𝗼-𝗱𝗮𝘆𝘀, primarily focused on security feature bypass and privilege escalation. 𝗧𝗿𝗮𝗰𝗸𝗲𝗱 𝗖𝗩𝗘𝘀: 🔸 CVE-2026-21514 🔸 CVE-2026-21510 🔸 CVE-2026-21513 🔸 CVE-2026-21525 🔸 CVE-2026-21533 🔸 CVE-2026-21519 Multiple SYSTEM-level 𝗲𝗹𝗲𝘃𝗮𝘁𝗶𝗼𝗻-𝗼𝗳-𝗽𝗿𝗶𝘃𝗶𝗹𝗲𝗴𝗲 issues and 𝘂𝘀𝗲𝗿-𝗶𝗻𝘁𝗲𝗿𝗮𝗰𝘁𝗶𝗼𝗻 𝗱𝗼𝗰𝘂𝗺𝗲𝗻𝘁 𝗮𝘁𝘁𝗮𝗰𝗸𝘀 are already being exploited in the wild — making endpoint patch prioritization critical. 𝗙𝘂𝗹𝗹 𝗯𝗿𝗲𝗮𝗸𝗱𝗼𝘄𝗻 and insights available in this month’s 𝗛𝗼𝗿𝗶𝘇𝗼𝗻 𝗔𝗹𝗲𝗿𝘁: 🔗 https://horizon-secured.com/newsletter/ #HorizonAlert #Cybersecurity #PatchTuesday #ZeroDay

    Post summary

    Several CVE‑2026‑215xx vulnerabilities are actively exploited in the wild via privilege escalation and user‑interaction attacks, stressing the urgency of patching.

    020931.1K
    2.2K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(2/10追加) 🛡️No.1509 CVE-2026-21510 Microsoft Windows Shell Protection Mechanism Failure Vulnerability ============= CVSSスコア: 8.8 (Base) / Microsoft Corporation CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:保護メカニズムの不具合 (CWE-693 / Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、悪意のあるリンクやショートカットファイルを介して、リモートよりWindows SmartScreen および Windows Shell のセキュリティプロンプトをバイパスされる恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21510 🛡️No.1510 CVE-2026-21513 Microsoft MSHTML Framework Security Feature Bypass Vulnerability ============= CVSSスコア: 8.8 (Base) / Microsoft Corporation CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:保護メカニズムの不具合 (CWE-693 / Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、細工されたHTMLファイルやショートかっとファイルを介して、リモートから、セキュリティ機能をバイパスされる恐れがあります。 https://msrc.microsoft.com/update-guide/advisory/CVE-2026-21513 🛡️No.1511 CVE-2026-21514 Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability ============= CVSSスコア: 7.8 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:セキュリティ決定の信頼できない入力への依存 (CWE-807/ Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 認証済みの攻撃者により、Officeファイルを介してローカル上でSYSTEM権限を取得される恐れがります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21514 🛡️No.1512 CVE-2026-21519 Microsoft Windows Type Confusion Vulnerability ============= CVSSスコア: 7.8 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 種別:型の取り違え (CWE-843/ Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 認証済みの攻撃者により、ローカル上でSYSTEM権限を取得される恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21519 🛡️No.1513 CVE-2026-21525 Microsoft Windows NULL Pointer Dereference Vulnerability ============= CVSSスコア: 6.2 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 種別:NULL ポインタデリファレンス (CWE-476 / Microsoft Corporation) 深刻度:注意 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、ローカル上でDoSを発生させられる恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21525 🛡️No.1514 CVE-2026-21533 Windows Remote Desktop Services Elevation of Privilege Vulnerability ============= CVSSスコア: 7.8 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 種別:不適切な権限管理 (CWE-269 / Microsoft Corporation) 深刻度:深刻🔥 ---------------------- 悪用時影響: 認証済みの攻撃者により、ローカル上でSYSTEM権限を取得される恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21533 CISA Adds Six Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/02/10/cisa-adds-six-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA confirmed that six CVEs are actively exploited and added them to the KEV catalog; Microsoft has issued advisories, but no PoC or exploit code is mentioned.

    000834.7K
    42.5K followersView on X
  • PurpleBox@prplbx
    Active Exploitation

    The zero-days (all actively exploited): • CVE-2026-21510 — Windows Shell bypass (CVSS 8.8) • CVE-2026-21513 — MSHTML bypass (CVSS 8.8) • CVE-2026-21519 — DWM priv escalation (CVSS 7.8) • CVE-2026-21533 — RDP priv escalation (CVSS 7.8) Plus 2 critical Azure flaws - CVSS 9.8.

    Post summary

    The post confirms multiple zero‑day CVEs are actively exploited with high severity scores; no PoC, exploit code, patch, or false‑positive claim is provided.

    10010110
    101 followersView on X
  • @ByteVanguardSec@ByteVanguardSec
    Active Exploitation

    Fresh zero-day alert: CVE-2026-21519 – Type confusion flaw in Windows Desktop Window Manager (DWM) allows local priv esc from low-priv user → SYSTEM. Actively exploited in the wild, added to CISA KEV. Patched Feb 10 Patch Tuesday. Affects Win10/11 & Servers. Details + mitigations: https://bytevanguard.com/2026/02/12/cve-2026-21519-windows-dwm-zeroday/ Patch ASAP! #WindowsSecurity #PatchTuesday #CVE202621519"

    Post summary

    The post alerts about CVE‑2026‑21519, a type‑confusion flaw in Windows DWM enabling local privilege escalation, notes that it is actively exploited per CISA KEV, and confirms a Patch Tuesday update.

    01010103
    5 followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISA、6つの既知の脆弱性をカタログに追加 CISA Adds Six Known Exploited Vulnerabilities to Catalog #CISA (Feb 10) CVE-2026-21510 Microsoft Windows シェル保護メカニズムの失敗の脆弱性 CVE-2026-21513 Microsoft MSHTML フレームワークのセキュリティ機能バイパスの脆弱性 CVE-2026-21514 Microsoft Office Word のセキュリティ決定における信頼できない入力への依存の脆弱性 CVE-2026-21519 Microsoft Windows の型混乱の脆弱性 CVE-2026-21525 Microsoft Windows の NULL ポインタ逆参照の脆弱性 CVE-2026-21533 Windows リモート デスクトップ サービスの権限昇格の脆弱性 https://www.cisa.gov/news-events/alerts/2026/02/10/cisa-adds-six-known-exploited-vulnerabilities-catalog

    Post summary

    CISA has added six Microsoft vulnerabilities to its catalog, noting they are already known to be exploited in the wild, but the post does not provide any PoC, exploit code, patch, or debunking information.

    00011354
    4.7K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    2026年2月のMicrosoft 定例パッチで6つのゼロデイ脆弱性に対処、まずはWindows端末の優先適用を(CVE-2026-21519他) https://rocket-boys.co.jp/security-measures-lab/microsoft-february-2026-patch-fixes-6-zero-days-prioritize-windows-updates-cve-2026-21519/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    Microsoft released its February 2026 patch addressing six zero‑day vulnerabilities, including CVE‑2026‑21519, with priority for Windows devices.

    00020169
    318 followersView on X
  • Patel Mahendra@Mahendrak29
    Active Exploitation

    •CVE-2026-21510 – Windows Shell Security Feature Bypass (zero-day, public exploit) •CVE-2026-21513 – MSHTML Framework Security Feature Bypass (zero-day, public exploit) •CVE-2026-21519 – Desktop Window Manager Elevation of Privilege (actively exploited)

    Post summary

    Three zero-day CVEs (CVE‑2026‑21510, 21513, 21519) are publicly exploitable, with CVE‑2026‑21519 confirmed as actively exploited in the wild.

    10010134
  • CVE@CVEnew
    Disclosure

    CVE-2026-21519 Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally. https://www.cve.org/CVERecord?id=CVE-2026-21519

    Post summary

    A type‑confusion vulnerability in Windows Desktop Window Manager permits local privilege escalation, with no PoC, exploit, or patch discussed.

    00020471
    56.5K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:00 UTC: CVE-2026-21519 disclosed. CISA: CVE-2026-21519 added to Known Exploited Vulnerabilities — Microsoft Windows Status: ✅ Confirmed exploited in the wild Date added: 2026-02-10 Required action: Apply mitigations per vendor instructions, follow applicable BOD…

    Post summary

    CISA confirms CVE‑2026‑21519 is actively exploited in the wild, with vendor‑approved mitigations advised.

    1000045
    183 followersView on X
  • İmam Gazali@boo8ow1923
    Patch

    İşte güncel ve yamasız kritik güvenlik zafiyetlerinin CVE listesi, önem derecesine göre sıralanmış şekilde: ## Kritik Zafiyetler (CVSS 10.0 - En Yüksek Risk) - **Cisco Secure Firewall ürünleri**: Mart 2026 güncellemesinde 48 güvenlik açığı giderildi, bunlardan 2 tanesi CVSS 10.0 seviyesinde kritik açıklardır. Bu açıklar saldırganlara sistem kontrolü vermektedir.^4^ ## Sıfır Gün Açıkları (Aktif İstismar Riski) - **CVE-2026-21385**: Android için - sınırlı ve hedefli istismar edildiğine dair işaretler bulunan sıfır gün açığı^1^ - **CVE-2026-21510**: Windows Shell güvenlik özelliği atlama açığı^3^ - **CVE-2026-21513**: MSHTML Framework güvenlik özelliği atlama açığı^3^ - **CVE-2026-21514**: Microsoft Word güvenlik özelliği atlama açığı^3^ - **CVE-2026-21519**: Desktop Window Manager yetki yükseltme açığı^3^ - **CVE-2026-21533**: Remote Desktop Services yetki yükseltme açığı^3^ - **CVE-2026-21525**: Remote Access Connection Manager hizmet aksatma açığı^3^ ## Google Chrome Kritik Açıkları - **CVE-2026-3536**: ANGLE'da tamsayı taşması (Kritik)^10^ - **CVE-2026-3537**: PowerVR'da nesne yaşam döngüsü sorunu (Kritik)^10^ - **CVE-2026-3538**: Skia'da tamsayı taşması (Kritik)^10^ ## Yüksek Önemli Açıklar - **CVE-2026-3539**: DevTools'da nesne yaşam döngüsü sorunu (Yüksek)^10^ - **CVE-2026-3540**: WebAudio'da uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3541**: CSS'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3542**: WebAssembly'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3543**: V8'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3544**: WebCodecs'da heap buffer overflow (Yüksek)^10^ - **CVE-2026-3545**: Navigasyonda yetersiz veri doğrulama (Yüksek)^10^ ## Güncelleme Önerileri - **Windows 11**: KB5077181 (25H2/24H2) ve KB5075941 (23H2) güncellemeleri ile 6 sıfır gün açığı kapatıldı^3^ - **Android**: 2026-03-05 güvenlik yama seviyesi veya üzeri tüm açıkları giderir^1,2^ - **Google Chrome**: En son sürüme güncelleme yapılması kritik açıklar için zorunludur^1^ - **Cisco ürünleri**: Mart 2026 paket güvenlik güncellemesinin uygulanması gerekir^4^ Bu zafiyetler arasında özellikle sıfır gün açıkları ve CVSS 10.0 seviyesindeki açıklar en yüksek riski taşımaktadır ve acil olarak yamanması gerekmektedir.

    Post summary

    The post lists numerous high‑severity CVEs, highlights signs of active exploitation for at least one zero‑day, and provides detailed patch and update recommendations to mitigate the risks.

    0100071
    48 followersView on X
  • برهان الجابري@brhan_alja99287
    General

    السيطرة الكاملة (CVE-2026-21519 & 21533) 🔑 ثغرات "تصعيد الامتيازات". هنا تكمن الخطورة الكبرى؛ فهي تسمح للمهاجم (الذي قد يكون دخل لجهازك بصلاحية محدودة) أن يتحول إلى "مدير نظام" (SYSTEM). النتيجة؟ التحكم في كل ملف، كاميرا، وميكروفون في جهازك!

    Post summary

    The tweet notes that CVE‑2026‑21519 and CVE‑2026‑21533 are privilege‑escalation flaws that could let an attacker with limited access become SYSTEM and control device resources, but provides no additional details or evidence.

    1000049
    761 followersView on X
  • kawn@kawn2020
    Patch

    「CVE-2026-21510、CVE-2026-21513、CVE-2026-21514、CVE-2026-21519、CVE-2026-21525、CVE-2026-21533 の脆弱性について、Microsoft 社では悪用の事実を確認済みと公表しており、今後被害が拡大するおそれがあるため、至急、セキュリティ更新プログラムを適用してくだ…」 https://x.com/kawn2020/status/2021830907704095189

    Post summary

    Microsoft confirms exploitation of several CVEs and urges users to apply security updates immediately to prevent further damage.

    10000152
    89 followersView on X
  • transilienceai@transilienceai
    General

    @MachinaRecord - CVE-2026-21519: デスクトップウィンドウマネージャーの特権昇格

    Post summary

    The tweet simply identifies CVE‑2026‑21519 as a privilege‑escalation flaw in the Desktop Window Manager.

    1000038
    315 followersView on X
  • kawn@kawn2020
    Disclosure

    #windowsupdate #microsoft (つづき) ・CVE-2026-21513 MSHTML Framework のセキュリティ機能のバイパスの脆弱性 ・CVE-2026-21514 Microsoft Word のセキュリティ機能のバイパスの脆弱性 ・CVE-2026-21519 デスクトップ ウィンドウ マネージャーの特権の昇格の脆弱性 (つづく…)

    Post summary

    The post announces three newly disclosed CVEs affecting MSHTML Framework, Microsoft Word, and the Desktop Window Manager, providing brief technical descriptions.

    10000124
    89 followersView on X
  • xplynx (read: ksplinks)@xplynx
    Disclosure

    - CVE-2026-21514 (CVSS 7.8): Office Word untrusted inputs; local security bypass via Office files. - CVE-2026-21519 (CVSS 7.8): Desktop Window Manager type confusion; local privilege escalation to SYSTEM.

    Post summary

    The text announces two new CVEs with CVSS 7.8, describing local security bypass in Word and privilege escalation via Desktop Window Manager, but provides no PoC, exploit code, or mitigation information.

    1000038
    550 followersView on X
  • kawn@kawn2020
    Active Exploitation

    #windowsupdate #microsoft ●悪用可能性 -悪用の事実を確認済み:6 件 ・CVE-2026-21510 8.8 Windows シェル ・CVE-2026-21513 8.8 Internet Explorer ・CVE-2026-21514 7.8 Microsoft Office Word ・CVE-2026-21519 7.8 デスクトップ ウィンドウ マネージャー … https://x.com/kawn2020/status/2021554147150139768

    Post summary

    The tweet confirms that CVEs 2026-21510, 21513, 21514, and 21519 have been actively exploited in the wild, providing CVSS scores and affected components, but does not mention PoCs, exploits, patches, or technical details beyond that.

    10000176
    89 followersView on X
  • Grok@grok
    Active Exploitation

    Here's a summary of the six actively exploited zero-days patched by Microsoft: - CVE-2026-21510 (CVSS 8.8): Windows Shell protection failure; allows network-based security bypass. - CVE-2026-21513 (CVSS 8.8): MSHTML flaw; bypasses prompts for malicious files via HTML. - CVE-2026-21514 (CVSS 7.8): Office Word untrusted inputs; local security bypass via Office files. - CVE-2026-21519 (CVSS 7.8): Desktop Window Manager type confusion; local privilege escalation to SYSTEM. - CVE-2026-21525 (CVSS 6.2): Remote Access Connection Manager null pointer; local DoS. - CVE-2026-21533 (CVSS 7.8): Remote Desktop privilege mismanagement; local escalation to SYSTEM. Update ASAP!

    Post summary

    Microsoft has patched six zero‑day CVEs that were actively exploited, covering shell protection failures, HTML and Office file issues, privilege escalation, and denial of service.

    00010466
    8.1M followersView on X
  • Grok@grok
    Active Exploitation

    Here are key security bug fixes in the Feb 2026 Windows 11 update (KB5075941): - CVE-2026-21510: Windows Shell bypasses SmartScreen via malicious links (exploited). - CVE-2026-21513: MSHTML bypasses network security (exploited). - CVE-2026-21514: Word bypasses OLE mitigations (exploited). - CVE-2026-21519: Desktop Window Manager privilege escalation (exploited). - CVE-2026-21525: Remote Access DoS via null pointer (exploited). - CVE-2026-21533: Remote Desktop privilege elevation (exploited). Also fixes Secure Boot certs, VSM shutdown issues, Defender logging, and GPU security checks. Total: 58 flaws patched. For full list, check Microsoft's update guide.

    Post summary

    The February 2026 Windows 11 update addresses several CVEs that were actively exploited in the wild, providing fixes and highlighting the severity of the vulnerabilities.

    10000311
    8.1M followersView on X
  • Prateek Tomar@TomarPrateek23
    Disclosure

    New vulnerability disclosed: CVE-2026-21519. Microsoft Windows Type Confusion Vulnerability. Worth reviewing if this affects your stack. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #Microsoft

    Post summary

    The post announces a newly disclosed Microsoft Windows type confusion vulnerability (CVE-2026-21519) and directs readers to a link for more details, but provides no PoC, exploit code, or patch information.

    0001059
    76 followersView on X
CPE platform detail21 entries

21 of 21 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more