CVE-2026-21533Active Exploitation(microsoft / windows_10_1607)

CRITICALCVSS 7.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 22 mentions and remains active

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-03. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-269

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Active exploitation appears in 33 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 68 mentions across 22 observed days

What's happening

  • Active exploitation reported across 33 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 33 signals
  • Technical details provided in 41 signals
  • General: 10 classified signals
  • Peaked 20d ago at 22 mentions (2026-02-11); latest day: 2
  • 68 total mentions across 22 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_server_2012windows_server_2016windows_server_2019

2 versions affected across 13 products

Deep dive

Activity timeline68 mentions / 22d
06111722Mentions · 2026-02-10: 6Mentions · 2026-02-11: 22Mentions · 2026-02-12: 7Mentions · 2026-02-13: 1Mentions · 2026-02-14: 1Mentions · 2026-02-18: 1Mentions · 2026-02-19: 1Mentions · 2026-02-20: 1Mentions · 2026-02-24: 1Mentions · 2026-03-02: 1Mentions · 2026-03-04: 1Mentions · 2026-03-06: 1Mentions · 2026-03-07: 1Mentions · 2026-03-08: 4Mentions · 2026-03-09: 5Mentions · 2026-03-10: 6Mentions · 2026-03-11: 1Mentions · 2026-03-12: 1Mentions · 2026-03-13: 2Mentions · 2026-03-22: 1Mentions · 2026-03-25: 1Mentions · 2026-05-08: 2PoC Mentioned / Linked · 2026-02-10: 1PoC Mentioned / Linked · 2026-02-11: 1PoC Mentioned / Linked · 2026-03-09: 1PoC Mentioned / Linked · 2026-03-10: 2Exploit Tool / Code · 2026-02-11: 2Active Exploitation · 2026-02-10: 3Active Exploitation · 2026-02-11: 13Active Exploitation · 2026-02-12: 5Active Exploitation · 2026-02-13: 1Active Exploitation · 2026-02-14: 1Active Exploitation · 2026-02-24: 1Active Exploitation · 2026-03-09: 1Active Exploitation · 2026-03-10: 3Active Exploitation · 2026-03-12: 1Active Exploitation · 2026-03-13: 1Active Exploitation · 2026-03-22: 1Active Exploitation · 2026-05-08: 2Patch / Workaround · 2026-02-10: 2Patch / Workaround · 2026-02-11: 14Patch / Workaround · 2026-02-12: 4Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-03-08: 2Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-03-10: 5Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-13: 2Patch / Workaround · 2026-05-08: 1Technical Details · 2026-02-10: 5Technical Details · 2026-02-11: 18Technical Details · 2026-02-12: 1Technical Details · 2026-02-14: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-24: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 1Technical Details · 2026-03-08: 2Technical Details · 2026-03-09: 2Technical Details · 2026-03-10: 4Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-22: 102-1002-1202-1402-1902-2403-0403-0703-0903-1103-1303-2505-08
Signal classification6 categories
Active Exploitation
2841.2%
Patch
1522.1%
General
1014.7%
Disclosure
913.2%
Exploit
57.4%
PoC
11.5%
Referenced assets47 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-106
Active Exploitation3Disclosure2Patch1
2026-02-1122
Active Exploitation10Disclosure3Exploit1General4Patch4
2026-02-127
Active Exploitation3Patch4
2026-02-131
Active Exploitation1
2026-02-141
Active Exploitation1
2026-02-181
Patch1
2026-02-191
General1
2026-02-201
General1
2026-02-241
Active Exploitation1
2026-03-021
General1
2026-03-041
Disclosure1
2026-03-061
Exploit1
2026-03-071
Disclosure1
2026-03-084
Exploit2Patch2
2026-03-095
Active Exploitation1Disclosure1General2Patch1
2026-03-106
Active Exploitation3Patch2PoC1
2026-03-111
Disclosure1
2026-03-121
Active Exploitation1
2026-03-132
Active Exploitation1Exploit1
2026-03-221
Active Exploitation1
2026-03-251
General1
2026-05-082
Active Exploitation2
Full discourse20 posts
  • Cyber Security News@The_Cyber_News
    Active Exploitation

    🚨 Windows Remote Desktop Services 0-Day Vulnerability Exploited in the Wild Source: https://cybersecuritynews.com/windows-remote-desktop-services-0-day-vulnerability/ Microsoft has patched CVE-2026-21533, a zero-day elevation of privilege vulnerability in Windows Remote Desktop Services (RDS) that attackers are exploiting in the wild to gain SYSTEM-level access. The flaw stems from improper privilege management and was addressed in the February 2026 Patch Tuesday updates released on February 10. It requires no user interaction and affects the unchanged scope, impacting confidentiality, integrity, and availability at high levels. The vulnerability arises from flawed privilege handling in RDS components. #cybersecuritynews #vulnerability #microsoft

    Post summary

    The article reports that CVE-2026-21533, a zero‑day privilege escalation in Windows Remote Desktop Services, is actively exploited in the wild and has been patched by Microsoft in February 2026.

    71671164329457.0K
    48.0K followersView on X
  • Dark Web Informer@DarkWebInformer
    Exploit

    ‼️ A threat Actor claims to be selling a zero-day exploit of CVE-2026-21533 for $220,000. The exploit is a Windows Remote Desktop Services privilege escalation vulnerability. It includes improper privilege management in Windows Remote Desktop that could allow an authorized attacker to elevate privileges locally on a compromised system.

    Post summary

    A threat actor claims to sell a zero‑day exploit for CVE‑2026‑21533, a Windows Remote Desktop privilege‑elevation vulnerability, but no PoC, code, patch, or evidence of active use is provided.

    73039187.4K
    170.6K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CISA has added 6 vulnerabilities to the KEV Catalog CVE-2026-21513: Microsoft Internet Explorer Protection Mechanism Failure Vulnerability: Microsoft Internet Explorer contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. CVE-2026-21525: Microsoft Windows NULL Pointer Dereference Vulnerability: Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally. CVE-2026-21510: Microsoft Windows Shell Protection Mechanism Failure Vulnerability: Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. CVE-2026-21533: Microsoft Windows Improper Privilege Management Vulnerability: Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally. CVE-2026-21519: Microsoft Windows Type Confusion Vulnerability: Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally. CVE-2026-21514: Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability: Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally.

    Post summary

    CISA has announced the addition of six new CVEs to its KEV Catalog, providing brief descriptions of their impact but no details on exploitation or mitigation.

    09124104.8K
    164.8K followersView on X
  • 情報の灯台@joho_no_todai
    Patch

    Windowsの修正済み脆弱性に、闇市場で約3,480万円の値札がぶら下がる。 CVE-2026-21533。パッチは1か月前に出た。 売り手が賭けているのは技術ではなく、パッチを当てない組織の数だ。 攻撃者にとっての「ゼロデイ」は、未発見の欠陥ではなく未適用のパッチだ。 https://note.com/joho_no_todai/n/n2c18d65d1db8

    Post summary

    The post notes that the CVE‑2026‑21533 Windows vulnerability, now patched, is being sold on the dark market for ~34.8 million yen, underscoring attackers’ focus on organizations that have yet to apply the available fix.

    0302128.7K
    5.8K followersView on X
  • EcuCERT@EcuCERT_EC
    Patch

    Microsoft publica parche para CVE-2026-21533 en Windows Remote Desktop Services, vulnerabilidad 0-day que permite elevación local de privilegios (CWE-269). Mas información: https://www.ecucert.gob.ec/wp-content/uploads/2026/02/Al-2026-007-Vulnerabilidad-0-Day-CVE-2026-21533-en-Windows-RDS-Elevacion-de-Privilegios.pdf #PorUnEcuadorCiberseguro @Arcotel_ec @CsirtCEDIA @CsirtEPN https://t.co/oLBSV4Ht7q

    Post summary

    Microsoft has issued a patch for the CVE-2026-21533 local privilege elevation vulnerability in Windows Remote Desktop Services, with further technical details available in the linked PDF.

    050123712
    1.9K followersView on X
  • BleepingComputer@BleepinComputer
    Active Exploitation

    Our Microsoft February 2026 Patch Tuesday article was updated to include some information on how CVE-2026-21533 and CVE-2026-21525 were found to be exploited.

    Post summary

    Microsoft updated its Patch Tuesday article to reveal that CVE-2026-21533 and CVE-2026-21525 were being exploited in the wild, though no PoC or exploit code was disclosed.

    0301504.0K
    248.1K followersView on X
  • Horizon Secured@horizon_secured
    Active Exploitation

    🚨 𝗛𝗼𝗿𝗶𝘇𝗼𝗻 𝗔𝗹𝗲𝗿𝘁 – 𝗙𝗲𝗯𝗿𝘂𝗮𝗿𝘆 𝟮𝟬𝟮𝟲 𝗣𝗮𝘁𝗰𝗵 𝗧𝘂𝗲𝘀𝗱𝗮𝘆 February brings 𝟲 𝗮𝗰𝘁𝗶𝘃𝗲𝗹𝘆 𝗲𝘅𝗽𝗹𝗼𝗶𝘁𝗲𝗱 𝘇𝗲𝗿𝗼-𝗱𝗮𝘆𝘀, primarily focused on security feature bypass and privilege escalation. 𝗧𝗿𝗮𝗰𝗸𝗲𝗱 𝗖𝗩𝗘𝘀: 🔸 CVE-2026-21514 🔸 CVE-2026-21510 🔸 CVE-2026-21513 🔸 CVE-2026-21525 🔸 CVE-2026-21533 🔸 CVE-2026-21519 Multiple SYSTEM-level 𝗲𝗹𝗲𝘃𝗮𝘁𝗶𝗼𝗻-𝗼𝗳-𝗽𝗿𝗶𝘃𝗶𝗹𝗲𝗴𝗲 issues and 𝘂𝘀𝗲𝗿-𝗶𝗻𝘁𝗲𝗿𝗮𝗰𝘁𝗶𝗼𝗻 𝗱𝗼𝗰𝘂𝗺𝗲𝗻𝘁 𝗮𝘁𝘁𝗮𝗰𝗸𝘀 are already being exploited in the wild — making endpoint patch prioritization critical. 𝗙𝘂𝗹𝗹 𝗯𝗿𝗲𝗮𝗸𝗱𝗼𝘄𝗻 and insights available in this month’s 𝗛𝗼𝗿𝗶𝘇𝗼𝗻 𝗔𝗹𝗲𝗿𝘁: 🔗 https://horizon-secured.com/newsletter/ #HorizonAlert #Cybersecurity #PatchTuesday #ZeroDay

    Post summary

    The announcement details six zero‑day CVEs (CVE‑2026‑21514, 21510, 21513, 21525, 21533, 21519) that are actively exploited, enabling privilege escalation and feature bypass, and stresses the urgent need for patching.

    020931.1K
    2.2K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(2/10追加) 🛡️No.1509 CVE-2026-21510 Microsoft Windows Shell Protection Mechanism Failure Vulnerability ============= CVSSスコア: 8.8 (Base) / Microsoft Corporation CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:保護メカニズムの不具合 (CWE-693 / Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、悪意のあるリンクやショートカットファイルを介して、リモートよりWindows SmartScreen および Windows Shell のセキュリティプロンプトをバイパスされる恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21510 🛡️No.1510 CVE-2026-21513 Microsoft MSHTML Framework Security Feature Bypass Vulnerability ============= CVSSスコア: 8.8 (Base) / Microsoft Corporation CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:保護メカニズムの不具合 (CWE-693 / Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、細工されたHTMLファイルやショートかっとファイルを介して、リモートから、セキュリティ機能をバイパスされる恐れがあります。 https://msrc.microsoft.com/update-guide/advisory/CVE-2026-21513 🛡️No.1511 CVE-2026-21514 Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability ============= CVSSスコア: 7.8 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:セキュリティ決定の信頼できない入力への依存 (CWE-807/ Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 認証済みの攻撃者により、Officeファイルを介してローカル上でSYSTEM権限を取得される恐れがります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21514 🛡️No.1512 CVE-2026-21519 Microsoft Windows Type Confusion Vulnerability ============= CVSSスコア: 7.8 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 種別:型の取り違え (CWE-843/ Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 認証済みの攻撃者により、ローカル上でSYSTEM権限を取得される恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21519 🛡️No.1513 CVE-2026-21525 Microsoft Windows NULL Pointer Dereference Vulnerability ============= CVSSスコア: 6.2 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 種別:NULL ポインタデリファレンス (CWE-476 / Microsoft Corporation) 深刻度:注意 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、ローカル上でDoSを発生させられる恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21525 🛡️No.1514 CVE-2026-21533 Windows Remote Desktop Services Elevation of Privilege Vulnerability ============= CVSSスコア: 7.8 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 種別:不適切な権限管理 (CWE-269 / Microsoft Corporation) 深刻度:深刻🔥 ---------------------- 悪用時影響: 認証済みの攻撃者により、ローカル上でSYSTEM権限を取得される恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21533 CISA Adds Six Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/02/10/cisa-adds-six-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA confirmed that six CVEs were actively exploited and added them to its catalog, providing Microsoft advisories that include patch information.

    000834.7K
    42.5K followersView on X
  • Machina Record@MachinaRecord
    Patch

    🔨マイクロソフト、攻撃で悪用されているゼロデイ6件などを修正(CVE-2026-21533、CVE-2026-21525ほか) 🩹Fortinet、深刻度の高いFortiSandboxとFortiOSの脆弱性にパッチ(CVE-2025-52436、CVE-2026-22153) 〜サイバーアラート 2月11~12日〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/43837/

    Post summary

    Microsoft and Fortinet have released patches for actively exploited CVEs, addressing zero‑day vulnerabilities with high severity.

    11010208
    1.2K followersView on X
  • VaultEdge IT Solutions@VaultEdgeIT
    Active Exploitation

    🚨 Windows RDS 0-Day Exploited in the Wild Microsoft patches CVE-2026-21533, a high-severity privilege escalation flaw in Windows Remote Desktop Services actively used to gain SYSTEM access. 🔗 https://cybersecuritynews.com/windows-remote-desktop-services-0-day-vulnerability/ #CyberSecurity #Windows #RDS #ZeroDay #CVE #PatchTuesday https://t.co/JikVY59Tdk

    Post summary

    CVE‑2026‑21533 is a high‑severity privilege escalation flaw in Windows RDS that is being actively exploited to gain SYSTEM access, and Microsoft has issued a patch.

    01020116
    35 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Critical zero-day in Windows RDS (CVE-2026-21533) exploited to gain SYSTEM privileges. Patch now to secure your systems! Link: https://thedailytechfeed.com/microsoft-patches-critical-zero-day-in-windows-rds-exploited-for-system-privilege-escalation/ #Vulnerability #Exploit #Security #Patch #Update #Microsoft #RDS #CVE #System #Privilege #Escalation #Threat #Protection #Defense #Cyber #Windows #Tech #Alert #Risk #Mitigation

    Post summary

    Critical zero‑day CVE‑2026‑21533 in Windows RDS has been exploited for SYSTEM privilege escalation; Microsoft has released a patch that users should apply immediately.

    01020131
    234 followersView on X
  • Matt Van Bibber@mattvanbibber
    General

    @pjcolbeck Few more... hope they were patched 🤣 CVE-2025-58718 CVE-2025-58737 CVE-2025-59202 CVE-2025-60703 CVE-2026-21533

    Post summary

    The tweet lists several CVE identifiers with no additional details, merely expressing hope they have been patched.

    00020158
    1.4K followersView on X
  • dbugs@ptdbugs
    PoC

    Sale of a 1-day exploit for vulnerability CVE-2026-21533 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-21533) For informational purposes only. CVE-2026-21533 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-21533) is a local privilege escalation (LPE) vulnerability in the Windows Remote Desktop Services component. Improper privilege management allows an authenticated user to escalate their level of access, up to and including adding a new account to the local Administrators group. Vulnerability type: LPE OS: Windows 10 - Windows 11; Windows Server 2012 - Windows Server 2025 Price: 220000$ #dbugs_darkweb

    Post summary

    The post announces the sale of a 1‑day exploit for CVE‑2026‑21533, confirming a PoC exists, but offers no evidence of active exploitation, patching, or detailed exploit code.

    00002122
    554 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-1086 2 - CVE-2022-40982 3 - CVE-2025-24252 4 - CVE-2025-55182 5 - CVE-2026-21533 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post highlights the top five trending CVEs but provides no additional technical, exploit, or patch information.

    00020213
    1.7K followersView on X
  • PurpleBox@prplbx
    Active Exploitation

    The zero-days (all actively exploited): • CVE-2026-21510 — Windows Shell bypass (CVSS 8.8) • CVE-2026-21513 — MSHTML bypass (CVSS 8.8) • CVE-2026-21519 — DWM priv escalation (CVSS 7.8) • CVE-2026-21533 — RDP priv escalation (CVSS 7.8) Plus 2 critical Azure flaws - CVSS 9.8.

    Post summary

    The post lists several zero‑day CVEs that are currently being exploited, providing brief technical descriptors and CVSS scores to highlight their severity.

    10010110
    101 followersView on X
  • Ajay Prakash@Im_AjayPrakash
    Active Exploitation

    ⚠️ WINDOWS USERS: CRITICAL SECURITY ALERT ⚠️ A major "Zero-Day" flaw (CVE-2026-21533) has been found in Windows Remote Desktop. Hackers are already using this to secretly take full control of computers! https://t.co/T3u0pov0Ob

    Post summary

    The tweet warns that CVE-2026-21533 is currently being exploited to gain remote control of Windows systems, but it offers no technical or mitigation details.

    1100076
    70 followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISA、6つの既知の脆弱性をカタログに追加 CISA Adds Six Known Exploited Vulnerabilities to Catalog #CISA (Feb 10) CVE-2026-21510 Microsoft Windows シェル保護メカニズムの失敗の脆弱性 CVE-2026-21513 Microsoft MSHTML フレームワークのセキュリティ機能バイパスの脆弱性 CVE-2026-21514 Microsoft Office Word のセキュリティ決定における信頼できない入力への依存の脆弱性 CVE-2026-21519 Microsoft Windows の型混乱の脆弱性 CVE-2026-21525 Microsoft Windows の NULL ポインタ逆参照の脆弱性 CVE-2026-21533 Windows リモート デスクトップ サービスの権限昇格の脆弱性 https://www.cisa.gov/news-events/alerts/2026/02/10/cisa-adds-six-known-exploited-vulnerabilities-catalog

    Post summary

    CISA announced adding six CVEs to its catalog as known exploited vulnerabilities, but did not provide PoC, exploit code, patches, or debunking information.

    00011354
    4.7K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Active Exploitation

    Windows Remote Desktop Services 0-Day Vulnerability Exploited in the Wild to Escalate Privileges https://cybersecuritynews.com/windows-remote-desktop-services-0-day-vulnerability/ "Microsoft has patched CVE-2026-21533, a zero-day elevation of privilege vulnerability in Windows Remote Desktop Services (RDS) that attackers are exploiting"

    Post summary

    Microsoft patched CVE-2026-21533, a zero‑day privilege escalation in Windows Remote Desktop Services that attackers are actively exploiting in the wild.

    01010216
    3.4K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:00 UTC: CVE-2026-21533 disclosed. CISA: CVE-2026-21533 added to Known Exploited Vulnerabilities — Microsoft Windows Status: ✅ Confirmed exploited in the wild Date added: 2026-02-10 Required action: Apply mitigations per vendor instructions, follow applicable BOD…

    Post summary

    CVE-2026‑21533 is confirmed to be exploited in the wild, with CISA adding it to the Known Exploited Vulnerabilities list and urging users to apply vendor‑issued mitigations.

    1000043
    186 followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    Windows RDS の脆弱性 CVE-2026-21533:ダーク Web で販売されるエクスプロイトとは? https://iototsecnews.jp/2026/03/08/hackers-allegedly-selling-exploit-for-windows-remote-desktop-services-0-day-flaw/ Windows Remote Desktop Services (RDS) における、深刻な脆弱性である CVE-2026-21533 について解説する記事です。この問題の根本的な原因は、システム内での権限管理が不適切に行われていることにあります。本来であれば、ユーザーやプロセスごとに厳密に制限されるべき操作ですが、その割り当てや検証が正しく機能していないため、意図しない制御が可能な領域が生まれてしまっています。この隙を突かれると、標準的な権限しか持たない利用者であっても、システム全体の操作ができる管理者権限を不正に取得できてしまいます。まずは OS のアップデートを確実に行い、不要なサービスは動かさないといった、基本的な対策を意識すべきです。 #CVE202621533 #Exploit #Microsoft #Vulnerability #WindowsRemoteDesktopServices #ZeroDay

    Post summary

    The article reports that CVE-2026-21533, a privilege escalation flaw in Windows RDS, is being sold on the dark web, indicating potential active exploitation, and recommends OS updates and disabling unnecessary services.

    01000135
    484 followersView on X
CPE platform detail23 entries

23 of 23 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x96
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more