CISA has added six Microsoft zero-day vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation in the wild. The flaws span Windows Shell, MSHTML, Office Word, Desktop Window Manager, Remote Access Connection Manager, and Remote Desktop Services — covering privilege escalation, security bypasses, and denial-of-service attacks.
Microsoft released patches in its February 2026 Patch Tuesday. Federal agencies must remediate by CISA's deadlines under Binding Operational Directive 22-01. Nation-state groups, including China's Salt Typhoon, are among those exploiting similar flaws. All organizations should apply patches immediately and audit exposure across Office, RDS, and remote access tools.
Source: Cybersecurity News