Skip to content
Microsoft issues urgent patches for actively exploited Windows, Office zero

Microsoft issues urgent patches for actively exploited Windows, Office zero

Storyboard18 February 12, 2026

Microsoft has rolled out critical security updates for Windows and Office after confirming that several zero-day vulnerabilities were being used in active attacks.

The company said the flaws were exploited before patches became available, allowing hackers to compromise systems with limited user interaction. In some instances, clicking a malicious link on a Windows device could trigger an attack. Another vulnerability could be exploited through a specially crafted Office file.

Microsoft warned that technical details describing how to exploit the bugs have now been made public, potentially increasing the risk to unpatched systems. The company did not specify where those details were published. In its advisory, Microsoft credited researchers from Google’s Threat Intelligence Group for identifying the vulnerabilities.

Also read: AI fears are overblown, says Mahindra Group CEO Anish Shah; calls it a tailwind for IT services

One of the most severe flaws, tracked as CVE-2026-21510, affects the Windows shell, a core element of the operating system’s interface. Microsoft said the issue impacts all supported versions of Windows. Exploitation could allow attackers to bypass SmartScreen, a built-in security feature designed to alert users to suspicious links or downloads.

Security researcher Dustin Childs said the vulnerability enables remote code execution. Although it requires user interaction, he noted that one-click exploits capable of running malicious code are uncommon and valuable to threat actors.

Google confirmed that the Windows shell vulnerability had been widely exploited. Successful attacks could result in the covert installation of malware with elevated privileges, raising the risk of ransomware, persistent system compromise, or data collection.

Microsoft also addressed another actively exploited flaw, CVE-2026-21513, in MSHTML, the legacy browser engine originally used by Internet Explorer. While Internet Explorer has been retired, MSHTML remains part of modern Windows systems for compatibility purposes. The vulnerability could allow attackers to bypass security safeguards and deploy malware.

Also read: ‘Short-term thinking will kill them’: Databricks CEO says SaaS firms risk collapse in AI era

Independent security journalist Brian Krebs reported that Microsoft fixed at least three additional zero-day vulnerabilities that were also under active exploitation.

Microsoft is urging users and organisations to apply the latest updates immediately, cautioning that public disclosure of exploit techniques may accelerate further attacks against systems that remain unpatched.