Claude is having a major outage. Status board · Discuss Claude

Patch Tuesday: February 2026

Each month's Microsoft security updates: what to patch first, the Critical fixes, and what CISA says attackers are exploiting.

How to use it Start with "Patch these first" for the fixes attackers are already using. Then filter the list by product or keyword, or tick "Critical only" to narrow it down.

Next Patch Tuesday: Tue 13 Oct 2026 (in 3 days)

February 2026 Patch Tuesday: Microsoft fixed 54 vulnerabilities, 2 of them Critical. 6 were already being exploited. Released Tue 10 Feb 2026.

  • 54vulnerabilities fixed
  • 2Critical
  • 6exploited before the fix
  • 3publicly disclosed
  • 6now on CISA KEV

By type: 23 elevation of privilege, 11 remote code execution, 7 spoofing, 5 information disclosure, 5 security feature bypass, 3 denial of service.

Update problems? Ask in Patch Tuesday & Updates. From October 2026 a “what broke for you?” thread opens there at 1 pm Eastern every Patch Tuesday.

Patch these first

Being exploited, already public, or on CISA’s list of vulnerabilities attackers are using. Whatever else waits for testing, these should not.

CVEWhatSeverityCVSSWhy first
CVE-2026-21510Windows Shell Security Feature BypassImportant8.8Exploited Publicly disclosed On CISA KEV federal deadline 3 Mar
CVE-2026-21513MSHTML Framework Security Feature BypassImportant8.8Exploited Publicly disclosed On CISA KEV federal deadline 3 Mar
CVE-2026-21514Microsoft Word Security Feature BypassImportant7.8Exploited Publicly disclosed On CISA KEV federal deadline 3 Mar
CVE-2026-21519Desktop Window Manager Elevation of PrivilegeImportant7.8Exploited On CISA KEV federal deadline 3 Mar
CVE-2026-21533Windows Remote Desktop Services Elevation of PrivilegeImportant7.8Exploited On CISA KEV federal deadline 3 Mar
CVE-2026-21525Windows Remote Access Connection Manager Denial of ServiceModerate6.2Exploited On CISA KEV federal deadline 3 Mar

Critical (2)

Microsoft’s top rating: usually code execution with little or no user action.

CVEWhatImpactCVSS
CVE-2026-21522Microsoft ACI Confidential Containers Elevation of PrivilegeElevation of Privilege6.7
CVE-2026-23655Microsoft ACI Confidential Containers Information DisclosureInformation Disclosure6.5

Added to CISA KEV in February 2026 (28)

Every vendor, not only Microsoft. CISA adds a vulnerability when it has evidence attackers are using it. US federal agencies must fix it by the deadline shown; for everyone else, it is the best free “patch this now” list there is.

CVEVendor and productWhatAddedFederal deadlineRansomware
CVE-2022-20775Cisco SD-WANPath Traversal25 Feb27 Feb 2026
CVE-2026-20127Cisco Catalyst SD-WAN Controller and ManagerAuthentication Bypass25 Feb27 Feb 2026
CVE-2026-25108Soliton Systems K.K FileZenOS Command Injection24 Feb17 Mar 2026
CVE-2025-49113Roundcube WebmailRoundCube Webmail Deserialization of Untrusted Data20 Feb13 Mar 2026
CVE-2025-68461Roundcube WebmailRoundCube Webmail Cross-site Scripting20 Feb13 Mar 2026
CVE-2021-22175GitLab GitLabGitLab Server-Side Request Forgery (SSRF)18 Feb11 Mar 2026
CVE-2026-22769Dell RecoverPoint for Virtual Machines (RP4VMs)Use of Hard-coded Credentials18 Feb21 Feb 2026
CVE-2008-0015Microsoft Windows Microsoft Windows Video ActiveX Control Remote Code Execution17 Feb10 Mar 2026
CVE-2020-7796Synacor Zimbra Collaboration Suite(ZCS) Server-Side Request Forgery17 Feb10 Mar 2026
CVE-2024-7694TeamT5 ThreatSonar Anti-RansomwareUnrestricted Upload of File with Dangerous Type17 Feb10 Mar 2026
CVE-2026-2441Google ChromiumCSS Use-After-Free17 Feb10 Mar 2026
CVE-2026-1731BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)OS Command Injection13 Feb16 Feb 2026Known
CVE-2024-43468Microsoft Configuration ManagerSQL Injection12 Feb5 Mar 2026
CVE-2025-15556Notepad++ Notepad++Notepad++ Download of Code Without Integrity Check12 Feb5 Mar 2026
CVE-2025-40536SolarWinds Web Help DeskSecurity Control Bypass12 Feb15 Feb 2026
CVE-2026-20700Apple Multiple ProductsApple Multiple Buffer Overflow12 Feb5 Mar 2026
CVE-2026-21510Microsoft WindowsShell Protection Mechanism Failure10 Feb3 Mar 2026
CVE-2026-21513Microsoft WindowsMicrosoft MSHTML Framework Protection Mechanism Failure10 Feb3 Mar 2026
CVE-2026-21514Microsoft OfficeWord Reliance on Untrusted Inputs in a Security Decision10 Feb3 Mar 2026
CVE-2026-21519Microsoft WindowsType Confusion10 Feb3 Mar 2026
CVE-2026-21525Microsoft WindowsNULL Pointer Dereference10 Feb3 Mar 2026
CVE-2026-21533Microsoft WindowsImproper Privilege Management10 Feb3 Mar 2026
CVE-2025-11953React Native Community CLIOS Command Injection5 Feb26 Feb 2026
CVE-2026-24423SmarterTools SmarterMailMissing Authentication for Critical Function5 Feb26 Feb 2026Known
CVE-2019-19006Sangoma FreePBX Sangoma FreePBX Improper Authentication3 Feb24 Feb 2026
CVE-2021-39935GitLab Community and Enterprise EditionsServer-Side Request Forgery (SSRF)3 Feb24 Feb 2026
CVE-2025-40551SolarWinds Web Help DeskDeserialization of Untrusted Data3 Feb6 Feb 2026
CVE-2025-64328Sangoma FreePBX Sangoma FreePBX OS Command Injection3 Feb24 Feb 2026

All 54 fixes

Show the full list, with a filter
CVEProductWhatSeverityCVSS
CVE-2026-21522Azure Compute GalleryMicrosoft ACI Confidential Containers Elevation of PrivilegeCritical6.7
CVE-2026-23655Azure Compute GalleryMicrosoft ACI Confidential Containers Information DisclosureCritical6.5
CVE-2026-21531Azure SDKAzure SDK for Python Remote Code ExecutionImportant9.8
CVE-2026-21255Role: Windows Hyper-VWindows Hyper-V Security Feature BypassImportant8.8
CVE-2026-21256GitHub Copilot and Visual StudioGitHub Copilot and Visual Studio Remote Code ExecutionImportant8.8
CVE-2026-21510Windows ShellWindows Shell Security Feature BypassImportant8.8
CVE-2026-21513MSHTML FrameworkMSHTML Framework Security Feature BypassImportant8.8
CVE-2026-21516Github CopilotGitHub Copilot for Jetbrains Remote Code ExecutionImportant8.8
CVE-2026-21518GitHub Copilot and Visual Studio CodeGitHub Copilot and Visual Studio Code Security Feature BypassImportant8.8
CVE-2026-21537Microsoft Defender for LinuxMicrosoft Defender for Endpoint Linux Extension Remote Code ExecutionImportant8.8
CVE-2026-21228Azure LocalAzure Local Remote Code ExecutionImportant8.1
CVE-2026-21229Power BIPower BI Remote Code ExecutionImportant8.0
CVE-2026-21257GitHub Copilot and Visual StudioGitHub Copilot and Visual Studio Elevation of PrivilegeImportant8.0
CVE-2026-21523GitHub Copilot and Visual StudioGitHub Copilot and Visual Studio Code Remote Code ExecutionImportant8.0
CVE-2026-20841Windows Notepad AppWindows Notepad App Remote Code ExecutionImportant7.8
CVE-2026-21231Windows KernelWindows Kernel Elevation of PrivilegeImportant7.8
CVE-2026-21232Windows HTTP.sysWindows HTTP.sys Elevation of PrivilegeImportant7.8
CVE-2026-21236Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.8
CVE-2026-21238Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.8
CVE-2026-21239Windows KernelWindows Kernel Elevation of PrivilegeImportant7.8
CVE-2026-21240Windows HTTP.sysWindows HTTP.sys Elevation of PrivilegeImportant7.8
CVE-2026-21245Windows KernelWindows Kernel Elevation of PrivilegeImportant7.8
CVE-2026-21246Microsoft Graphics ComponentWindows Graphics Component Elevation of PrivilegeImportant7.8
CVE-2026-21250Windows HTTP.sysWindows HTTP.sys Elevation of PrivilegeImportant7.8
CVE-2026-21251Windows Cluster Client FailoverCluster Client Failover (CCF) Elevation of PrivilegeImportant7.8
CVE-2026-21259Microsoft Office ExcelMicrosoft Excel Elevation of PrivilegeImportant7.8
CVE-2026-21514Microsoft Office WordMicrosoft Word Security Feature BypassImportant7.8
CVE-2026-21519Desktop Window ManagerDesktop Window Manager Elevation of PrivilegeImportant7.8
CVE-2026-21533Windows Remote DesktopWindows Remote Desktop Services Elevation of PrivilegeImportant7.8
CVE-2026-20846Windows GDI+GDI+ Denial of ServiceImportant7.5
CVE-2026-21218.NET.NET SpoofingImportant7.5
CVE-2026-21243Windows LDAP – Lightweight Directory Access ProtocolWindows Lightweight Directory Access Protocol (LDAP) Denial of ServiceImportant7.5
CVE-2026-21260Microsoft Office OutlookMicrosoft Outlook SpoofingImportant7.5
CVE-2026-21511Microsoft Office OutlookMicrosoft Outlook SpoofingImportant7.5
CVE-2026-21235Microsoft Graphics ComponentWindows Graphics Component Elevation of PrivilegeImportant7.3
CVE-2026-21244Role: Windows Hyper-VWindows Hyper-V Remote Code ExecutionImportant7.3
CVE-2026-21247Role: Windows Hyper-VWindows Hyper-V Remote Code ExecutionImportant7.3
CVE-2026-21248Role: Windows Hyper-VWindows Hyper-V Remote Code ExecutionImportant7.3
CVE-2026-21234Windows Connected Devices Platform ServiceWindows Connected Devices Platform Service Elevation of PrivilegeImportant7.0
CVE-2026-21237Windows Subsystem for LinuxWindows Subsystem for Linux Elevation of PrivilegeImportant7.0
CVE-2026-21241Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.0
CVE-2026-21242Windows Subsystem for LinuxWindows Subsystem for Linux Elevation of PrivilegeImportant7.0
CVE-2026-21253Mailslot File SystemMailslot File System Elevation of PrivilegeImportant7.0
CVE-2026-21508Windows StorageWindows Storage Elevation of PrivilegeImportant7.0
CVE-2026-21512Azure DevOps ServerAzure DevOps Server Cross-Site ScriptingImportant6.5
CVE-2026-21527Microsoft Exchange ServerMicrosoft Exchange Server SpoofingImportant6.5
CVE-2026-21528Azure IoT ExplorerAzure IoT Explorer Information DisclosureImportant6.5
CVE-2026-21529Azure HDInsightsAzure HDInsight SpoofingImportant5.7
CVE-2026-21222Windows KernelWindows Kernel Information DisclosureImportant5.5
CVE-2026-21258Microsoft Office ExcelMicrosoft Excel Information DisclosureImportant5.5
CVE-2026-21261Microsoft Office ExcelMicrosoft Excel Information DisclosureImportant5.5
CVE-2026-21517Windows App for MacWindows App for Mac Installer Elevation of PrivilegeImportant4.7
CVE-2026-21249Windows NTLMWindows NTLM SpoofingImportant3.3
CVE-2026-21525Windows Remote Access Connection ManagerWindows Remote Access Connection Manager Denial of ServiceModerate6.2

Published later in the month (7)

Microsoft Edge updates, out-of-band fixes and cloud services. “Fixed by Microsoft” means a cloud service Microsoft has already patched: there is nothing to install.

DateCVEWhatSeverityAction
5 FebCVE-2026-24300Azure Front Door Elevation of PrivilegeCriticalFixed by Microsoft
17 FebCVE-2026-26119Windows Admin Center Elevation of PrivilegeCriticalUpdate
5 FebCVE-2026-24302Azure Arc Elevation of PrivilegeCriticalFixed by Microsoft
5 FebCVE-2026-21532Azure Function Information DisclosureCriticalFixed by Microsoft
19 FebCVE-2026-21535Microsoft Teams Information DisclosureCriticalFixed by Microsoft
5 FebCVE-2026-0391Microsoft Edge (Chromium-based) for Android SpoofingModerateUpdate
17 FebCVE-2026-0102Microsoft Edge (Chromium-based) Defense in DepthLowUpdate

From Microsoft’s Security Update Guide and CISA’s Known Exploited Vulnerabilities catalog, checked 6 hours ago. Only vulnerabilities Microsoft itself issued are counted; Chromium fixes that Edge inherits are left out. For known problems with the updates themselves, see Windows release health.

← All tools