Trinetri logo
Updated monthly

Microsoft Patch Tuesday
February 2026

Microsoft's February 2026 Patch Tuesday fixes 60 vulnerabilities across Windows, Azure and Microsoft Office - 7 rated Critical, 3 publicly disclosed before the patch shipped, 6 already exploited in the wild. Patch CVE-2026-21510 first.

Released February 10, 2026, 10:00 PT6 actively exploited3 publicly disclosed29 KB articles to deploy

February 2026 Patch Tuesday at a glance

60
Microsoft CVEs
excl. Edge & Azure Linux
7
Critical
12% of the release
6
Actively exploited
CVE-2026-21510
3
Publicly disclosed
known before the patch
9.8
Highest CVSS
CVE-2026-21531
29
KB articles
what you actually deploy

Why this number differs from other roundups. Microsoft's February 2026 release document lists 172 entries. 92 are Azure Linux (Mariner) OS package updates and 20 are republished Chromium fixes for Edge - neither is a Microsoft product vulnerability. The 60 above is the real Patch Tuesday set. See the breakdown →

Priority order

Patch these first

Ranked by exploitation reality, not score alone. This month's exploited flaw is rated Important - a severity-sorted list would bury it.

Patch today

Exploited in the wild

Confirmed attacks are already happening. Emergency change window.

CVE-2026-21510Windows Shell Security Feature Bypass VulnerabilityImportantCVSS 8.8BypassKB5075897CVE-2026-21513MSHTML Framework Security Feature Bypass VulnerabilityImportantCVSS 8.8BypassKB5075897CVE-2026-21514Microsoft Word Security Feature Bypass VulnerabilityImportantCVSS 7.8BypassCVE-2026-21519Desktop Window Manager Elevation of Privilege VulnerabilityImportantCVSS 7.8EoPKB5075897CVE-2026-21533Windows Remote Desktop Services Elevation of Privilege VulnerabilityImportantCVSS 7.8EoPKB5075897CVE-2026-21525Windows Remote Access Connection Manager Denial of Service VulnerabilityModerateCVSS 6.2DoSKB5075897

Patch this week

Publicly disclosed

Details are already public. Working exploits typically follow within days.

Nothing was disclosed before the patch shipped.

Patch this cycle

Critical remote code execution

No known exploitation yet, but network-reachable and high impact.

No Critical remote code execution fixes this month.

The numbers

What’s in this release

Where the 172 entries actually come from

Most roundups quote a single number. These are three unrelated release streams.

60 Microsoft products92 Azure Linux (Mariner)20 Edge (Chromium)

Severity

Microsoft channel only · 60 CVEs

February 2026 severity breakdown
Critical7
Important52
Moderate1
Low0

Impact type

What an attacker gains if it works

February 2026 impact breakdown
Elevation of Privilege26
Remote Code Execution12
Information Disclosure7
Spoofing7
Security Feature Bypass5
Denial of Service3

Most-affected components

Where this month’s fixes concentrate - filter by any of them in the table below

Role: Windows Hyper-V4Windows Kernel4GitHub Copilot and Visual Studio3Microsoft Office Excel3Windows Ancillary Function Driver for WinSock3Windows HTTP.sys3Azure Compute Gallery2Microsoft Graphics Component2Microsoft Office Outlook2Windows Subsystem for Linux2.NET1Azure Arc1
Every patch

Browse all 172 entries

Sorted by risk by default: exploited first, then publicly disclosed, then severity, then CVSS. Search by CVE, title, component or KB number.

Showing 60 of 60
60 Microsoft vulnerabilities in the February 2026 Patch Tuesday, sortable by severity, CVSS and exploit status.
TitleStatusKB
ImportantCVE-2026-21510Windows Shell Security Feature Bypass VulnerabilityBypass8.8ExploitedDisclosedWindows Shell5075897 +13
ImportantCVE-2026-21513MSHTML Framework Security Feature Bypass VulnerabilityBypass8.8ExploitedDisclosedMSHTML Framework5075897 +13
ImportantCVE-2026-21514Microsoft Word Security Feature Bypass VulnerabilityBypass7.8ExploitedDisclosedMicrosoft Office Word
ImportantCVE-2026-21519Desktop Window Manager Elevation of Privilege VulnerabilityEoP7.8ExploitedDesktop Window Manager5075897 +11
ImportantCVE-2026-21533Windows Remote Desktop Services Elevation of Privilege VulnerabilityEoP7.8ExploitedWindows Remote Desktop5075897 +13
ModerateCVE-2026-21525Windows Remote Access Connection Manager Denial of Service VulnerabilityDoS6.2ExploitedWindows Remote Access Connection Manager5075897 +13
CriticalCVE-2026-26119Windows Admin Center Elevation of Privilege VulnerabilityEoP8.8More likelyWindows Admin Center
ImportantCVE-2026-21231Windows Kernel Elevation of Privilege VulnerabilityEoP7.8More likelyWindows Kernel5075897 +13
ImportantCVE-2026-21238Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEoP7.8More likelyWindows Ancillary Function Driver for WinSock5075897 +13
ImportantCVE-2026-21511Microsoft Outlook Spoofing VulnerabilitySpoofing7.5More likelyMicrosoft Office Outlook5002833 +5
ImportantCVE-2026-21241Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEoP7.0More likelyWindows Ancillary Function Driver for WinSock5075897 +8
ImportantCVE-2026-21253Mailslot File System Elevation of Privilege VulnerabilityEoP7.0More likelyMailslot File System5075897 +13
CriticalCVE-2026-21522Microsoft ACI Confidential Containers Elevation of Privilege VulnerabilityEoP6.7Azure Compute Gallery
CriticalCVE-2026-23655Microsoft ACI Confidential Containers Information Disclosure VulnerabilityInfo Disc.6.5Azure Compute Gallery
ImportantCVE-2026-21531Azure SDK for Python Remote Code Execution VulnerabilityRCE9.8Azure SDK
ImportantCVE-2026-21255Windows Hyper-V Security Feature Bypass VulnerabilityBypass8.8Role: Windows Hyper-V5075897 +11
ImportantCVE-2026-21256GitHub Copilot and Visual Studio Remote Code Execution VulnerabilityRCE8.8GitHub Copilot and Visual Studio
ImportantCVE-2026-21516GitHub Copilot for Jetbrains Remote Code Execution VulnerabilityRCE8.8Github Copilot
ImportantCVE-2026-21518GitHub Copilot and Visual Studio Code Security Feature Bypass VulnerabilityBypass8.8GitHub Copilot and Visual Studio Code
ImportantCVE-2026-21537Microsoft Defender for Endpoint Linux Extension Remote Code Execution VulnerabilityRCE8.8Microsoft Defender for Linux
ImportantCVE-2026-21228Azure Local Remote Code Execution VulnerabilityRCE8.1Azure Local
ImportantCVE-2026-21257GitHub Copilot and Visual Studio Elevation of Privilege VulnerabilityEoP8.0GitHub Copilot and Visual Studio
ImportantCVE-2026-21523GitHub Copilot and Visual Studio Code Remote Code Execution VulnerabilityRCE8.0GitHub Copilot and Visual Studio
ImportantCVE-2026-20841Windows Notepad App Remote Code Execution VulnerabilityRCE7.8Windows Notepad App
ImportantCVE-2026-21232Windows HTTP.sys Elevation of Privilege VulnerabilityEoP7.8Windows HTTP.sys5075897 +6
Your move

What your IT team should do

The same five steps every month, in the order that reduces risk fastest.

Test the known-issue candidates

Check the Windows release health dashboard before promoting past ring 1, and have the rollback path written down before you need it. Kernel, networking and authentication fixes are the ones that historically break things.

12 Patch Management Best Practices for 2026

Verify installed state, then evidence it

Confirm the patch is actually present on each endpoint rather than trusting that "deployment succeeded". Keep the resulting report - it is the artefact auditors ask for, and reconstructing it later is far more work than capturing it now.

Patch Management: The Complete Guide

Trinetri does steps two through five automatically - detecting the 29 KB articles across every endpoint, staging them in rings, verifying installed state and producing the compliance evidence. See patch management →

Patch Tuesday FAQ

Patch Tuesday falls on the second Tuesday of every month, with updates going live at 10:00 a.m. Pacific Time. Microsoft introduced the practice in October 2003, following the Blaster worm, to cut distribution costs and give administrators a predictable cadence instead of patches arriving at random. The 10:00 a.m. timing is deliberate: it leaves a full working week to remediate before the weekend. Internally Microsoft calls it the "B" release; optional "C" and "D" preview releases follow later in the month. The next Patch Tuesday is September 8, 2026.

Microsoft fixed 60 vulnerabilities in February 2026, across Windows, Azure, Microsoft Office and Developer Tools. 7 are rated Critical, 3 were publicly disclosed before the patch shipped, and 6 were already being exploited. Note that Microsoft's release document lists 172 entries in total, but 92 of those are Azure Linux package updates and 20 are republished Chromium fixes for Edge, which is why other sources sometimes quote a much larger number.

Exploit Wednesday is the day after Patch Tuesday. Attackers compare the newly released patches against the previous version to locate the flaw each one fixes, then build working exploits from that difference - often within 24 to 48 hours. It is the reason the deployment window matters as much as the patch itself: every hour a Critical remote code execution fix sits undeployed is an hour of measurable exposure.

A workable target for most organisations: actively exploited vulnerabilities within 24 hours, publicly disclosed ones within 72 hours, remaining Critical fixes within seven days, and everything else within the month. CISA's Known Exploited Vulnerabilities catalogue sets binding deadlines for US federal agencies and is a reasonable benchmark for everyone else. Stage the rollout in rings rather than deploying everywhere at once, so a regression is caught on a pilot group instead of in production.

An out-of-band update is a patch released outside the monthly cycle because the risk will not wait for the next Patch Tuesday. Microsoft issues them for actively exploited flaws with no mitigation - most famously during the WannaCry outbreak in 2017, when it took the unusual step of patching versions of Windows that were already out of support.

Yes. Adobe aligned its releases with Patch Tuesday in November 2012, and both SAP's Security Patch Day and Oracle's quarterly Critical Patch Updates are coordinated to the same week. Part of the reason is defensive: staggered releases let attackers reverse-engineer one vendor's patch to find the same underlying flaw in another's still-unpatched product. For IT teams it means the second Tuesday is rarely just a Microsoft problem.

Edge is built on Chromium, so most of its security fixes originate with the Chromium project and are republished by Microsoft under their own CVE identifiers. They ship on Chromium's cadence rather than the Patch Tuesday cycle, and they are delivered by Edge's own updater rather than Windows Update. Counting the 20 Edge entries alongside Microsoft product fixes would inflate the headline number and imply work for your Windows Update rings that does not exist.

Stop the sprawl. Eliminate the guesswork.

Ready to See Autonomous Endpoint Management in Action?

Experience how Trinetri transforms endpoint chaos into clarity. Try the 30 minute demo session, our experts will walk you through how AI-powered automation, real-time visibility, and unified control can secure your entire hybrid environment, without the overhead.