Back Isc.Sans.Edu Microsoft Patch Tuesday - January 2026, (Tue, Feb 10th)
Today's patch Tuesday addresses 59 different vulnerabilities (plus two Chromium vulnerabilities affecting Microsoft Edge). While this is a lower-than-normal number, this includes six vulnerabilities that are already exploited. Three vulnerabilities have already been exploited and made public. In addition, five critical vulnerabilities are included in this patch Tuesday.
Vulnerabilities of Interest:
The three already exploited and public vulnerabilities are very similar, but they affect different Windows components. The issue is that the user is not properly warned when executing code they downloaded. Technologies like SmartScreen are supposed to prevent this from happening. The components affect:
CVE-2026-21510 : Windows Shell.
CVE-2026-21513 : This affects the (legacy) Internet Explorer HTML rendering engine. It is still used by some Windows components, but not by the Edge browser.
CVE-2026-21514 : Microsoft Word.
In addition, we have three more already exploited vulnerabilities:
CVE-2026-21533 : A privilege escalation in Remote Desktop
CVE-2026-21519 : A type confusion vulnerability in Windows Manager
CVE-2026-21525 : A Windows Remote Access Connection Manager Denial of Service.
Three of the critical vulnerabilities are related to Microsoft Azure and have already been patched by Microsoft.
CVE-2026-23655 This vulnerability only affects Windows Defender on Linux and may lead to remote code execution.
-- Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu Twitter |
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
