<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

CISA Flagged Six Microsoft Zero-Days as Actively Exploited Back in February — Check You've Patched

Six Microsoft zero-days added to CISA's KEV Catalog in February 2026 remain a live risk for anyone who skipped that Patch Tuesday.
Content Team

CISA added six actively exploited Microsoft zero-days to its Known Exploited Vulnerabilities Catalog on 10 February 2026: CVE-2026-21510 (Windows Shell), CVE-2026-21513 (MSHTML), CVE-2026-21514 (Office Word), CVE-2026-21519 (Desktop Window Manager), CVE-2026-21525 (Remote Access Connection Manager) and CVE-2026-21533 (Remote Desktop Services).

Between them they cover privilege escalation, security feature bypasses and denial of service. Microsoft shipped fixes in its February 2026 Patch Tuesday, so anyone current on updates is covered — the risk sits with organisations that deferred that cycle.

Federal remediation deadlines have since changed. CISA replaced Binding Operational Directive 22-01 with BOD 26-04 on 10 June 2026, swapping flat timelines for a tiered model running from three days to 60 days depending on risk.

Nation-state groups, including China's Salt Typhoon, are among those exploiting similar flaws. All organisations should confirm the February patches are applied and audit exposure across Office, RDS and remote access tools.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo