Microsoft patches six actively exploited Windows flaws
Microsoft's February 2026 Patch Tuesday addresses multiple vulnerabilities, including six CVEs confirmed under active exploitation that could allow attackers to control systems.
Japan's IPA has issued an advisory following Microsoft's February 11, 2026 security update release, emphasizing the critical nature of six vulnerabilities currently being exploited in the wild. The affected CVEs are CVE-2026-21510, CVE-2026-21513, CVE-2026-21514, CVE-2026-21519, CVE-2026-21525, and CVE-2026-21533. Microsoft has confirmed active exploitation of these flaws, which could lead to application crashes, system compromise, and attacker control of affected devices.
The advisory urges immediate patching due to the risk of widespread exploitation. Organizations are directed to deploy the February Patch Tuesday updates promptly through Windows Update or managed deployment processes. IPA notes that security updates typically install automatically through Windows Update, but organizations with update management policies should prioritize the rollout. System restarts may be required to complete the patching process.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2025/0212-ms.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free