Patch Tuesday February 2026: what Microsoft shipped
Microsoft published its security updates on Tuesday, 10 February 2026.
On the day, the briefing reads Microsoft's advisories and this page lists what carried a flag. It stays here afterwards as the record.
Which flaws were flagged?
6 flagged by Microsoft as exploited at release.
3 flagged by Microsoft as publicly disclosed.
6 are in the CISA KEV catalog.
- CVE-2026-21510 Windows Shell Security Feature Bypass Vulnerability Exploited at release · Publicly disclosed · In KEV
- CVE-2026-21513 MSHTML Framework Security Feature Bypass Vulnerability Exploited at release · Publicly disclosed · In KEV
- CVE-2026-21514 Microsoft Word Security Feature Bypass Vulnerability Exploited at release · Publicly disclosed · In KEV
- CVE-2026-21519 Desktop Window Manager Elevation of Privilege Vulnerability Exploited at release · In KEV
- CVE-2026-21533 Windows Remote Desktop Services Elevation of Privilege Vulnerability Exploited at release · In KEV
- CVE-2026-21525 Windows Remote Access Connection Manager Denial of Service Vulnerability Exploited at release · In KEV
What PlainSec published
We hold 10 CVEs from Microsoft's 2026-Feb document. That is what our records reach, not the size of the release: it grows for weeks after the day.