Microsoft patches actively exploited February flaws
IPA warns six Microsoft vulnerabilities patched in the February 2026 update are already being exploited in the wild and urges immediate patching.
Japan's IPA issued an alert following Microsoft's February 2026 Patch Tuesday release, highlighting six vulnerabilities—CVE-2026-21510, CVE-2026-21513, CVE-2026-21514, CVE-2026-21519, CVE-2026-21525, and CVE-2026-21533—that Microsoft has confirmed are being actively exploited. The advisory does not specify affected products beyond generic Microsoft software, nor does it detail the exploitation techniques or attacker identities, but it stresses that successful exploitation could allow application crashes or full attacker control of affected systems.
IPA recommends organizations and individual users apply the security updates immediately via Windows Update or through managed patch deployment processes, noting that a reboot may be required. As details on exploitation vectors, threat actors, and specific attack campaigns are not disclosed in this bulletin, this alert should be treated as an urgent patch reminder rather than a full technical disclosure.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2025/0212-ms.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free