Microsoft patched multiple vulnerabilities in February 2026, with six CVEs actively…
Microsoft patched multiple vulnerabilities in February 2026, with six CVEs actively exploited in the wild requiring immediate patching.
On February 11, 2026 (Japan time), Microsoft released its monthly security update addressing multiple vulnerabilities across its product line. The Japan Information-technology Promotion Agency (IPA) issued an advisory warning that exploitation of these vulnerabilities could lead to application crashes, remote system compromise, and various other impacts.
Microsoft has confirmed active exploitation of six vulnerabilities: CVE-2026-21510, CVE-2026-21513, CVE-2026-21514, CVE-2026-21519, CVE-2026-21525, and CVE-2026-21533. Given the confirmed in-the-wild exploitation, IPA emphasizes immediate application of security updates to prevent further compromise. The advisory notes particular urgency due to the risk of expanding damage from these actively exploited flaws.
Organizations are advised to deploy patches immediately through Windows Update, which typically occurs automatically. Enterprise environments with centralized update management should prioritize deployment of these patches, noting that system restarts may be required to complete installation.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2025/0212-ms.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free