Cybersecuritynews
Microsoft Patches Zero-Day Vulnerability in Remote Desktop Services
First seen 12 Feb 2026, 01:27 UTC
•
•44.9
Export
Article Content
Browse articles
Microsoft has addressed CVE-2026-21533, a zero-day elevation of privilege vulnerability in Windows Remote Desktop Services, which is being actively exploited by attackers to gain SYSTEM-level access. The flaw, resulting from improper privilege management, was patched in the February 2026 Patch Tuesday updates released on February 10, 2026. A public proof of concept (PoC) for this vulnerability was made available on February 11, 2026.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2026-02-10
CVE-2026-21533 published and patched
2026-02-10
CVE-2026-21533 added to CISA KEV (active exploitation)
2026-02-11
First public PoC for CVE-2026-21533 released
More articles in this cluster
Continue Reading
Google Addresses Eighth Chrome Zero-Day Vulnerability in 2025
China-linked Cyber Group Expands Targeting to Southeastern Europe
China-Nexus APT UAT-7290 Targets South Asia Telecoms in Cyber Espionage Campaign
China-linked UAT-7290 Targets Telcos in Cyberespionage Campaign
UAT-7290 Cyber Espionage Targets South Asian Telecoms
APT28 Exploits MSHTML Zero-Day Vulnerability in Windows