Skip to content
Microsoft Patch Tuesday - January 2026, (Tue, Feb 10th)

Microsoft Patch Tuesday - January 2026, (Tue, Feb 10th)

Isc.Sans.Edu February 10, 2026

Today's patch Tuesday addresses 59 different vulnerabilities (plus two Chromium vulnerabilities affecting Microsoft Edge). While this is a lower-than-normal number, this includes six vulnerabilities that are already exploited. Three vulnerabilities have already been exploited and made public. In addition, five critical vulnerabilities are included in this patch Tuesday.

Vulnerabilities of Interest:

The three already exploited and public vulnerabilities are very similar, but they affect different Windows components. The issue is that the user is not properly warned when executing code they downloaded. Technologies like SmartScreen are supposed to prevent this from happening. The components affect:

CVE-2026-21510 : Windows Shell.

CVE-2026-21513 : This affects the (legacy) Internet Explorer HTML rendering engine. It is still used by some Windows components, but not by the Edge browser.

CVE-2026-21514 : Microsoft Word.

In addition, we have three more already exploited vulnerabilities:

CVE-2026-21533 : A privilege escalation in Remote Desktop

CVE-2026-21519 : A type confusion vulnerability in Windows Manager

CVE-2026-21525 : A Windows Remote Access Connection Manager Denial of Service.

Three of the critical vulnerabilities are related to Microsoft Azure and have already been patched by Microsoft.

CVE-2026-23655 This vulnerability only affects Windows Defender on Linux and may lead to remote code execution.

-- Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu Twitter |