Post by : Bianca Haleem
Microsoft has confirmed that hackers are actively exploiting multiple critical zero-day vulnerabilities in its Windows operating system and Microsoft Office suite. The company has released urgent security patches as part of its February 2026 Patch Tuesday update.
In its latest security advisory, Microsoft revealed that at least six zero-day vulnerabilities were being actively used in real-world attacks. Zero-day vulnerabilities are security flaws that attackers exploit before a fix becomes widely available. These types of bugs are especially dangerous because users have little protection until updates are installed.
Critical Vulnerabilities Identified
One of the most serious flaws is a Windows Shell security feature bypass tracked as CVE-2026-21510. This vulnerability allows attackers to trick users into clicking malicious links or opening dangerous shortcuts. Once opened, harmful code can run without triggering normal Windows security warnings.
Other major vulnerabilities include:
A security bypass in Microsoft 365 and Office OLE (Object Linking and Embedding).
Internet Explorer component flaws that may allow remote code execution.
Weaknesses in Office document handling routines that attackers can exploit through phishing emails or malicious attachments.
These vulnerabilities affect core Windows components and Office applications that are widely used across businesses and homes worldwide.
February Patch Tuesday Fixes Around 60 Issues
Microsoft’s February 2026 Patch Tuesday update addresses nearly 60 vulnerabilities in total. However, the six actively exploited zero-day flaws are receiving the highest attention from cybersecurity experts.
Security professionals warn that attackers can exploit some of these bugs using simple social engineering tactics, such as phishing emails or fake download links. In many cases, only minimal user interaction is required.
Growing Pattern of Zero-Day Exploitation
Security analysts say this situation reflects a broader industry trend. Zero-day vulnerabilities are increasingly being used by advanced persistent threat (APT) groups soon after disclosure. In past Patch Tuesday cycles, Microsoft has even released emergency out-of-band updates after active exploitation was detected.
Similar emergency zero-day updates have recently been issued by other major technology companies, including Google and Apple, showing that the cybersecurity threat landscape remains highly active.
What Users and Organisations Should Do
Cybersecurity experts strongly advise:
Installing the latest Windows and Office updates immediately.
Enabling automatic updates.
Limiting administrator privileges.
Educating users about phishing risks.
Avoiding suspicious links and attachments.
Timely patching remains the most effective defense against zero-day attacks.
Microsoft has emphasized that applying the February 2026 security updates as soon as possible is critical to reducing risk.
Mattel Revives Masters of the Universe Toys Ahead of Film Launch
Mattel reintroduces Masters of the Universe action figures in sync with a new movie, reigniting pass
China Carries Out Executions of 11 Ming Family Members for Myanmar Scams
China has executed 11 Ming family members for orchestrating extensive scams and illegal gambling ope
US Issues Urgent Warning to Iran Amid Military Buildup in Gulf Region
As US military presence increases, Trump urges Iran to negotiate on nuclear program and warns of str
Copper Prices Reach Historical Heights Amid Global Metal Surge
Copper prices peak as geopolitical issues and a weak dollar fuel demand, initiating a sweeping rise
New Zealand Claims Victory Over India by 50 Runs in T20 Match
New Zealand defeated India by 50 runs in the fourth T20I, keeping their hopes alive in the series de
BTS Tour Demand Surges: Mexico Requests More Concerts
Mexico's President seeks more BTS concerts due to overwhelming ticket demand as fans rush to secure