
Patch Now or Pay Later: Microsoft Fixes 54 Flaws, Including 6 Actively Exploited Zero-Days
February may be cold.
Microsoft Patch Tuesday? Not so much.
Microsoft’s February 2026 release addresses 54 vulnerabilities across:
Windows
Microsoft Office
Azure
GitHub Copilot
Visual Studio Code
Microsoft Exchange
Defender for Endpoint
Developer SDKs
And here’s the headline:
👉 Six zero-days were already disclosed or actively exploited before patches were released.
That’s not theoretical risk.
That’s live-fire exploitation.
🔎 The Numbers Breakdown
Vulnerability Type
Count
Elevation of Privilege
23
Remote Code Execution
11
Spoofing
7
Information Disclosure
5
Security Feature Bypass
5
Denial of Service
3
Total
54
Two vulnerabilities were rated Critical, with several high-impact RCE and privilege escalation flaws across cloud and endpoint environments.
Microsoft marked customer action as required for all listed CVEs.
Translation: Patch.
🚨 The Six Zero-Days
The most concerning vulnerabilities include:
CVE-2026-21514 – Word Security Feature Bypass
CVE-2026-21513 – MSHTML Framework Bypass
CVE-2026-21510 – Windows Shell Bypass
CVE-2026-21533 – Windows RDP Elevation of Privilege
CVE-2026-21525 – Remote Access Connection Manager DoS
CVE-2026-21519 – Desktop Window Manager Elevation of Privilege
These can potentially be chained.
For example:
Bypass protections → Execute code → Escalate privileges → Move laterally.
That’s full compromise territory.
☁️ Critical Cloud Risk: Azure Confidential Containers
Two of the most serious vulnerabilities impact Azure Compute Gallery:
CVE-2026-23655 – Information Disclosure (Critical)
CVE-2026-21522 – Elevation of Privilege (Critical)
These affect Azure Confidential Containers — environments designed specifically for high-security workloads.
If attackers can escalate privileges inside “confidential” computing infrastructure, the security model itself weakens.
Cloud-native environments are not immune.
💻 Developer Tool Exposure
This month also hits developers hard:
GitHub Copilot (multiple RCE & bypass issues)
Visual Studio Code
Azure SDK for Python
Defender for Endpoint (Linux extension)
That’s a direct line into DevOps pipelines.
Compromising developer tools means:
Source code exposure
Credential harvesting
CI/CD manipulation
Software supply chain risk
Modern attackers don’t just target endpoints.
They target the build environment.
🪟 Windows & Office Impact
Windows saw multiple EoP flaws, including:
HTTP.sys
Hyper-V
Storage subsystems
Desktop Window Manager
Office wasn’t spared:
Outlook spoofing flaws
Excel information disclosure & EoP
Word security bypass
In enterprise environments, these represent lateral movement accelerators.
🎯 What This Means for Enterprises
This month isn’t overwhelming in volume.
It’s dangerous in impact.
Six actively exploited vulnerabilities represent 10% of this release.
As Fortra’s Tyler Reguly noted:
“There’s not a lot of CVEs to deal with… but there’s actually a lot to unpack here.”
Attackers are moving fast.
Patch windows are shrinking.
🛡️ Recommended Actions
For enterprise environments:
✔ Prioritize zero-days and Critical Azure flaws
✔ Patch RDP, Office, and Windows privilege escalations
✔ Update GitHub Copilot and VS Code environments
✔ Review Azure Confidential Container deployments
✔ Validate Defender for Endpoint Linux installations
✔ Monitor MSRC for revisions
✔ Stage-test updates before production rollout
✔ Audit identity and MFA controls
If CISA adds these to the KEV catalog — which is likely — compliance timelines will tighten quickly.
🔥 The Bigger Trend
This Patch Tuesday reinforces three realities:
Cloud-native services are now first-class attack targets.
Developer tooling is a primary compromise vector.
Privilege escalation remains attackers’ favorite move.
It’s not about how many vulnerabilities were fixed.
It’s about how many were already being exploited.
