CVE-2026-21510

high

Description

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

From the Tenable Blog

February 2026 Microsoft Patch Tuesday | Tenable®
February 2026 Microsoft Patch Tuesday | Tenable®

Published: 2026-02-10

Microsoft patched six zero-day vulnerabilities that were exploited in the wild including CVE-2026-21510 and CVE-2026-21513.

References

https://www.proofpoint.com/us/blog/threat-insight/more-cves-same-playbook-2026-vulnerability-exploitation-wild

https://www.theregister.com/2026/04/29/microsoft_zero_click_exploit/

https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-windows-flaw-exploited-in-zero-day-attacks/

https://thehackernews.com/2026/04/cisa-adds-actively-exploited.html

https://thehackernews.com/2026/04/microsoft-confirms-active-exploitation.html

https://www.securityweek.com/incomplete-windows-patch-opens-door-to-zero-click-attacks/

https://www.malwarebytes.com/blog/news/2026/02/february-2026-patch-tuesday-includes-six-actively-exploited-zero-days

https://www.infosecurity-magazine.com/news/microsoft-six-zero-day-feb-2026/

https://www.helpnetsecurity.com/2026/02/11/february-2026-patch-tuesday/

https://thehackernews.com/2026/02/microsoft-patches-59-vulnerabilities.html

https://securityaffairs.com/187855/security/u-s-cisa-adds-microsoft-office-and-microsoft-windows-flaws-to-its-known-exploited-vulnerabilities-catalog.html

https://www.theregister.com/2026/02/10/microsofts_valentines_gift_to_admins/

https://www.securityweek.com/6-actively-exploited-zero-days-patched-by-microsoft-with-february-2026-updates/

https://www.cisa.gov/news-events/alerts/2026/02/10/cisa-adds-six-known-exploited-vulnerabilities-catalog

https://securityaffairs.com/187848/uncategorized/microsoft-patch-tuesday-security-updates-for-february-2026-fix-six-actively-exploited-zero-days.html

https://krebsonsecurity.com/2026/02/patch-tuesday-february-2026-edition/

https://cyberscoop.com/microsoft-patch-tuesday-february-2026/

Details

Source: Mitre, NVD

Published: 2026-02-10

Updated: 2026-02-11

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.06398