<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

CISA Adds Six Microsoft Zero-Days to Known Exploited Vulnerabilities Catalog

CISA flags six Microsoft zero-day flaws in KEV Catalog; urgent patching advised for federal agencies to prevent exploits by nation-state groups.
Content Team

CISA has added six Microsoft zero-day vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation in the wild. The flaws span Windows Shell, MSHTML, Office Word, Desktop Window Manager, Remote Access Connection Manager, and Remote Desktop Services — covering privilege escalation, security bypasses, and denial-of-service attacks.

Microsoft released patches in its February 2026 Patch Tuesday. Federal agencies must remediate by CISA's deadlines under Binding Operational Directive 22-01. Nation-state groups, including China's Salt Typhoon, are among those exploiting similar flaws. All organizations should apply patches immediately and audit exposure across Office, RDS, and remote access tools.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo