How to use it Start with "Patch these first" for the fixes attackers are already using. Then filter the list by product or keyword, or tick "Critical only" to narrow it down.
Next Patch Tuesday: Tue 13 Oct 2026 (in 3 days)
February 2026 Patch Tuesday: Microsoft fixed 54 vulnerabilities, 2 of them Critical. 6 were already being exploited. Released Tue 10 Feb 2026.
- 54vulnerabilities fixed
- 2Critical
- 6exploited before the fix
- 3publicly disclosed
- 6now on CISA KEV
By type: 23 elevation of privilege, 11 remote code execution, 7 spoofing, 5 information disclosure, 5 security feature bypass, 3 denial of service.
Update problems? Ask in Patch Tuesday & Updates. From October 2026 a “what broke for you?” thread opens there at 1 pm Eastern every Patch Tuesday.
Patch these first
Being exploited, already public, or on CISA’s list of vulnerabilities attackers are using. Whatever else waits for testing, these should not.
| CVE | What | Severity | CVSS | Why first |
|---|---|---|---|---|
CVE-2026-21510 | Windows Shell Security Feature Bypass | Important | 8.8 | Exploited Publicly disclosed On CISA KEV federal deadline 3 Mar |
CVE-2026-21513 | MSHTML Framework Security Feature Bypass | Important | 8.8 | Exploited Publicly disclosed On CISA KEV federal deadline 3 Mar |
CVE-2026-21514 | Microsoft Word Security Feature Bypass | Important | 7.8 | Exploited Publicly disclosed On CISA KEV federal deadline 3 Mar |
CVE-2026-21519 | Desktop Window Manager Elevation of Privilege | Important | 7.8 | Exploited On CISA KEV federal deadline 3 Mar |
CVE-2026-21533 | Windows Remote Desktop Services Elevation of Privilege | Important | 7.8 | Exploited On CISA KEV federal deadline 3 Mar |
CVE-2026-21525 | Windows Remote Access Connection Manager Denial of Service | Moderate | 6.2 | Exploited On CISA KEV federal deadline 3 Mar |
Critical (2)
Microsoft’s top rating: usually code execution with little or no user action.
| CVE | What | Impact | CVSS |
|---|---|---|---|
CVE-2026-21522 | Microsoft ACI Confidential Containers Elevation of Privilege | Elevation of Privilege | 6.7 |
CVE-2026-23655 | Microsoft ACI Confidential Containers Information Disclosure | Information Disclosure | 6.5 |
Added to CISA KEV in February 2026 (28)
Every vendor, not only Microsoft. CISA adds a vulnerability when it has evidence attackers are using it. US federal agencies must fix it by the deadline shown; for everyone else, it is the best free “patch this now” list there is.
| CVE | Vendor and product | What | Added | Federal deadline | Ransomware |
|---|---|---|---|---|---|
CVE-2022-20775 | Cisco SD-WAN | Path Traversal | 25 Feb | 27 Feb 2026 | |
CVE-2026-20127 | Cisco Catalyst SD-WAN Controller and Manager | Authentication Bypass | 25 Feb | 27 Feb 2026 | |
CVE-2026-25108 | Soliton Systems K.K FileZen | OS Command Injection | 24 Feb | 17 Mar 2026 | |
CVE-2025-49113 | Roundcube Webmail | RoundCube Webmail Deserialization of Untrusted Data | 20 Feb | 13 Mar 2026 | |
CVE-2025-68461 | Roundcube Webmail | RoundCube Webmail Cross-site Scripting | 20 Feb | 13 Mar 2026 | |
CVE-2021-22175 | GitLab GitLab | GitLab Server-Side Request Forgery (SSRF) | 18 Feb | 11 Mar 2026 | |
CVE-2026-22769 | Dell RecoverPoint for Virtual Machines (RP4VMs) | Use of Hard-coded Credentials | 18 Feb | 21 Feb 2026 | |
CVE-2008-0015 | Microsoft Windows | Microsoft Windows Video ActiveX Control Remote Code Execution | 17 Feb | 10 Mar 2026 | |
CVE-2020-7796 | Synacor Zimbra Collaboration Suite | (ZCS) Server-Side Request Forgery | 17 Feb | 10 Mar 2026 | |
CVE-2024-7694 | TeamT5 ThreatSonar Anti-Ransomware | Unrestricted Upload of File with Dangerous Type | 17 Feb | 10 Mar 2026 | |
CVE-2026-2441 | Google Chromium | CSS Use-After-Free | 17 Feb | 10 Mar 2026 | |
CVE-2026-1731 | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) | OS Command Injection | 13 Feb | 16 Feb 2026 | Known |
CVE-2024-43468 | Microsoft Configuration Manager | SQL Injection | 12 Feb | 5 Mar 2026 | |
CVE-2025-15556 | Notepad++ Notepad++ | Notepad++ Download of Code Without Integrity Check | 12 Feb | 5 Mar 2026 | |
CVE-2025-40536 | SolarWinds Web Help Desk | Security Control Bypass | 12 Feb | 15 Feb 2026 | |
CVE-2026-20700 | Apple Multiple Products | Apple Multiple Buffer Overflow | 12 Feb | 5 Mar 2026 | |
CVE-2026-21510 | Microsoft Windows | Shell Protection Mechanism Failure | 10 Feb | 3 Mar 2026 | |
CVE-2026-21513 | Microsoft Windows | Microsoft MSHTML Framework Protection Mechanism Failure | 10 Feb | 3 Mar 2026 | |
CVE-2026-21514 | Microsoft Office | Word Reliance on Untrusted Inputs in a Security Decision | 10 Feb | 3 Mar 2026 | |
CVE-2026-21519 | Microsoft Windows | Type Confusion | 10 Feb | 3 Mar 2026 | |
CVE-2026-21525 | Microsoft Windows | NULL Pointer Dereference | 10 Feb | 3 Mar 2026 | |
CVE-2026-21533 | Microsoft Windows | Improper Privilege Management | 10 Feb | 3 Mar 2026 | |
CVE-2025-11953 | React Native Community CLI | OS Command Injection | 5 Feb | 26 Feb 2026 | |
CVE-2026-24423 | SmarterTools SmarterMail | Missing Authentication for Critical Function | 5 Feb | 26 Feb 2026 | Known |
CVE-2019-19006 | Sangoma FreePBX | Sangoma FreePBX Improper Authentication | 3 Feb | 24 Feb 2026 | |
CVE-2021-39935 | GitLab Community and Enterprise Editions | Server-Side Request Forgery (SSRF) | 3 Feb | 24 Feb 2026 | |
CVE-2025-40551 | SolarWinds Web Help Desk | Deserialization of Untrusted Data | 3 Feb | 6 Feb 2026 | |
CVE-2025-64328 | Sangoma FreePBX | Sangoma FreePBX OS Command Injection | 3 Feb | 24 Feb 2026 |
All 54 fixes
Show the full list, with a filter
| CVE | Product | What | Severity | CVSS |
|---|---|---|---|---|
CVE-2026-21522 | Azure Compute Gallery | Microsoft ACI Confidential Containers Elevation of Privilege | Critical | 6.7 |
CVE-2026-23655 | Azure Compute Gallery | Microsoft ACI Confidential Containers Information Disclosure | Critical | 6.5 |
CVE-2026-21531 | Azure SDK | Azure SDK for Python Remote Code Execution | Important | 9.8 |
CVE-2026-21255 | Role: Windows Hyper-V | Windows Hyper-V Security Feature Bypass | Important | 8.8 |
CVE-2026-21256 | GitHub Copilot and Visual Studio | GitHub Copilot and Visual Studio Remote Code Execution | Important | 8.8 |
CVE-2026-21510 | Windows Shell | Windows Shell Security Feature Bypass | Important | 8.8 |
CVE-2026-21513 | MSHTML Framework | MSHTML Framework Security Feature Bypass | Important | 8.8 |
CVE-2026-21516 | Github Copilot | GitHub Copilot for Jetbrains Remote Code Execution | Important | 8.8 |
CVE-2026-21518 | GitHub Copilot and Visual Studio Code | GitHub Copilot and Visual Studio Code Security Feature Bypass | Important | 8.8 |
CVE-2026-21537 | Microsoft Defender for Linux | Microsoft Defender for Endpoint Linux Extension Remote Code Execution | Important | 8.8 |
CVE-2026-21228 | Azure Local | Azure Local Remote Code Execution | Important | 8.1 |
CVE-2026-21229 | Power BI | Power BI Remote Code Execution | Important | 8.0 |
CVE-2026-21257 | GitHub Copilot and Visual Studio | GitHub Copilot and Visual Studio Elevation of Privilege | Important | 8.0 |
CVE-2026-21523 | GitHub Copilot and Visual Studio | GitHub Copilot and Visual Studio Code Remote Code Execution | Important | 8.0 |
CVE-2026-20841 | Windows Notepad App | Windows Notepad App Remote Code Execution | Important | 7.8 |
CVE-2026-21231 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-21232 | Windows HTTP.sys | Windows HTTP.sys Elevation of Privilege | Important | 7.8 |
CVE-2026-21236 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.8 |
CVE-2026-21238 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.8 |
CVE-2026-21239 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-21240 | Windows HTTP.sys | Windows HTTP.sys Elevation of Privilege | Important | 7.8 |
CVE-2026-21245 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-21246 | Microsoft Graphics Component | Windows Graphics Component Elevation of Privilege | Important | 7.8 |
CVE-2026-21250 | Windows HTTP.sys | Windows HTTP.sys Elevation of Privilege | Important | 7.8 |
CVE-2026-21251 | Windows Cluster Client Failover | Cluster Client Failover (CCF) Elevation of Privilege | Important | 7.8 |
CVE-2026-21259 | Microsoft Office Excel | Microsoft Excel Elevation of Privilege | Important | 7.8 |
CVE-2026-21514 | Microsoft Office Word | Microsoft Word Security Feature Bypass | Important | 7.8 |
CVE-2026-21519 | Desktop Window Manager | Desktop Window Manager Elevation of Privilege | Important | 7.8 |
CVE-2026-21533 | Windows Remote Desktop | Windows Remote Desktop Services Elevation of Privilege | Important | 7.8 |
CVE-2026-20846 | Windows GDI+ | GDI+ Denial of Service | Important | 7.5 |
CVE-2026-21218 | .NET | .NET Spoofing | Important | 7.5 |
CVE-2026-21243 | Windows LDAP – Lightweight Directory Access Protocol | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service | Important | 7.5 |
CVE-2026-21260 | Microsoft Office Outlook | Microsoft Outlook Spoofing | Important | 7.5 |
CVE-2026-21511 | Microsoft Office Outlook | Microsoft Outlook Spoofing | Important | 7.5 |
CVE-2026-21235 | Microsoft Graphics Component | Windows Graphics Component Elevation of Privilege | Important | 7.3 |
CVE-2026-21244 | Role: Windows Hyper-V | Windows Hyper-V Remote Code Execution | Important | 7.3 |
CVE-2026-21247 | Role: Windows Hyper-V | Windows Hyper-V Remote Code Execution | Important | 7.3 |
CVE-2026-21248 | Role: Windows Hyper-V | Windows Hyper-V Remote Code Execution | Important | 7.3 |
CVE-2026-21234 | Windows Connected Devices Platform Service | Windows Connected Devices Platform Service Elevation of Privilege | Important | 7.0 |
CVE-2026-21237 | Windows Subsystem for Linux | Windows Subsystem for Linux Elevation of Privilege | Important | 7.0 |
CVE-2026-21241 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.0 |
CVE-2026-21242 | Windows Subsystem for Linux | Windows Subsystem for Linux Elevation of Privilege | Important | 7.0 |
CVE-2026-21253 | Mailslot File System | Mailslot File System Elevation of Privilege | Important | 7.0 |
CVE-2026-21508 | Windows Storage | Windows Storage Elevation of Privilege | Important | 7.0 |
CVE-2026-21512 | Azure DevOps Server | Azure DevOps Server Cross-Site Scripting | Important | 6.5 |
CVE-2026-21527 | Microsoft Exchange Server | Microsoft Exchange Server Spoofing | Important | 6.5 |
CVE-2026-21528 | Azure IoT Explorer | Azure IoT Explorer Information Disclosure | Important | 6.5 |
CVE-2026-21529 | Azure HDInsights | Azure HDInsight Spoofing | Important | 5.7 |
CVE-2026-21222 | Windows Kernel | Windows Kernel Information Disclosure | Important | 5.5 |
CVE-2026-21258 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 5.5 |
CVE-2026-21261 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 5.5 |
CVE-2026-21517 | Windows App for Mac | Windows App for Mac Installer Elevation of Privilege | Important | 4.7 |
CVE-2026-21249 | Windows NTLM | Windows NTLM Spoofing | Important | 3.3 |
CVE-2026-21525 | Windows Remote Access Connection Manager | Windows Remote Access Connection Manager Denial of Service | Moderate | 6.2 |
Published later in the month (7)
Microsoft Edge updates, out-of-band fixes and cloud services. “Fixed by Microsoft” means a cloud service Microsoft has already patched: there is nothing to install.
| Date | CVE | What | Severity | Action |
|---|---|---|---|---|
| 5 Feb | CVE-2026-24300 | Azure Front Door Elevation of Privilege | Critical | Fixed by Microsoft |
| 17 Feb | CVE-2026-26119 | Windows Admin Center Elevation of Privilege | Critical | Update |
| 5 Feb | CVE-2026-24302 | Azure Arc Elevation of Privilege | Critical | Fixed by Microsoft |
| 5 Feb | CVE-2026-21532 | Azure Function Information Disclosure | Critical | Fixed by Microsoft |
| 19 Feb | CVE-2026-21535 | Microsoft Teams Information Disclosure | Critical | Fixed by Microsoft |
| 5 Feb | CVE-2026-0391 | Microsoft Edge (Chromium-based) for Android Spoofing | Moderate | Update |
| 17 Feb | CVE-2026-0102 | Microsoft Edge (Chromium-based) Defense in Depth | Low | Update |
From Microsoft’s Security Update Guide and CISA’s Known Exploited Vulnerabilities catalog, checked 6 hours ago. Only vulnerabilities Microsoft itself issued are counted; Chromium fixes that Edge inherits are left out. For known problems with the updates themselves, see Windows release health.