Microsoft Patches Zero-Day Vulnerability in Remote Desktop Services

Microsoft Patches Zero-Day Vulnerability in Remote Desktop Services

First seen 12 Feb 2026, 01:27 UTC Cybersecuritynews 44.9

Article Content

Browse articles
ThreatCluster

Microsoft has addressed CVE-2026-21533, a zero-day elevation of privilege vulnerability in Windows Remote Desktop Services, which is being actively exploited by attackers to gain SYSTEM-level access. The flaw, resulting from improper privilege management, was patched in the February 2026 Patch Tuesday updates released on February 10, 2026. A public proof of concept (PoC) for this vulnerability was made available on February 11, 2026.

Timeline

2026-02-10
CVE-2026-21533 published and patched
2026-02-10
CVE-2026-21533 added to CISA KEV (active exploitation)
2026-02-11
First public PoC for CVE-2026-21533 released