Critical Alert: Microsoft Patches 6 Actively Exploited Zero-Days in Massive 59-Flaw Security Update
A deep dive into the latest Patch Tuesday update, the actively exploited vulnerabilities, and how attackers are weaponizing them.
Critical Alert: Microsoft Patches 6 Actively Exploited Zero-Days in Massive 59-Flaw Security Update
A deep dive into the latest Patch Tuesday update, the actively exploited vulnerabilities, and how attackers are weaponizing them.

In the ever-evolving landscape of cybersecurity, staying ahead of threat actors is a constant race against time. This Tuesday, tech giant Microsoft released a massive security update addressing a staggering 59 vulnerabilities across its software ecosystem.
While regular updates are standard practice, this month’s release has the cybersecurity community on high alert: six of these vulnerabilities are “zero-days” that are currently being actively exploited in the wild.
If you are an IT administrator, a cybersecurity professional, or even an everyday Windows user, understanding the scope of this update is absolutely crucial.
📊 By the Numbers: Breaking Down the 59 Flaws
The severity and categorization of these patched vulnerabilities provide a clear window into current attacker methodologies. Out of the 59 flaws:
- 5 are rated Critical
- 52 are rated Important
- 2 are rated Moderate
When looking at the types of vulnerabilities, the trend is clear — attackers are heavily focused on gaining deeper access once inside a system:
- Privilege Escalation: 25 flaws
- Remote Code Execution (RCE): 12 flaws
- Spoofing: 7 flaws
- Information Disclosure: 6 flaws
- Security Feature Bypass: 5 flaws
- Denial-of-Service (DoS): 3 flaws
- Cross-Site Scripting (XSS): 1 flaw
(Note: These are in addition to three security flaws Microsoft recently addressed in its Edge browser, including a Moderate spoofing vulnerability for Android).
🚨 The Primary Threat: 6 Actively Exploited Zero-Days
The most critical aspect of this month’s update is the patch for six zero-day vulnerabilities. Threat actors are already weaponizing these flaws. Here is what you need to know:
- CVE-2026–21510 (CVSS 8.8): A protection mechanism failure in Windows Shell allowing unauthorized attackers to bypass security features over a network.
- CVE-2026–21513 (CVSS 8.8): A severe flaw in the MSHTML Framework enabling network-based security feature bypass.
- CVE-2026–21514 (CVSS 7.8): A local security bypass in Microsoft Office Word caused by reliance on untrusted inputs.
- CVE-2026–21519 (CVSS 7.8): A ‘type confusion’ vulnerability in the Desktop Window Manager, allowing local privilege escalation.
- CVE-2026–21525 (CVSS 6.2): A null pointer dereference in the Windows Remote Access Connection Manager resulting in a local Denial of Service.
- CVE-2026–21533 (CVSS 7.8): Improper privilege management in Windows Remote Desktop that lets authorized attackers elevate their privileges locally.
🗣️ Expert Insights: How Hackers are Using These Flaws
Security researchers have shed light on how dangerous these vulnerabilities truly are.
Jack Bicer, Director of Vulnerability Research at Action1, highlighted the stealthy nature of the MSHTML flaw:
“CVE-2026–21513 is a security feature bypass vulnerability in the Microsoft MSHTML Framework… A crafted file can silently bypass Windows security prompts and trigger dangerous actions with a single click.”
For the local privilege escalation flaws, the threat lies in the post-compromise phase. Kev Breen from Immersive explains:
“These are local privilege escalation vulnerabilities, which means an attacker must have already gained access to a vulnerable host… Once on the host, the attacker can use these escalation vulnerabilities to elevate privileges to SYSTEM. With this level of access, a threat actor could disable security tooling, deploy additional malware, or access secrets that could lead to full domain compromise.”
Furthermore, CrowdStrike noted that the exploit for CVE-2026–21533 modifies a service configuration key, potentially allowing adversaries to add a new user directly to the Administrator group.
🏛️ Government Mandates and Future Protections
The severity of the situation has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add all six zero-days to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to apply fixes by March 3, 2026.
Secure Boot Certificate Renewal
Alongside these patches, Microsoft is rolling out updated Secure Boot certificates to replace the original 2011 certificates expiring in June 2026. Failing to receive these updates will push devices into a degraded security state, leaving them exposed to boot-level vulnerabilities.
Looking Ahead: Microsoft’s New Security Initiatives
To combat the rising tide of sophisticated attacks, Microsoft is introducing two new proactive defense mechanisms:
- Windows Baseline Security Mode: Moving toward runtime integrity safeguards enabled by default, ensuring only properly signed apps and drivers can run.
- User Transparency and Consent: Similar to macOS’s TCC framework, Windows will now provide clear, actionable prompts when apps try to access sensitive resources like the camera, microphone, or files.
🛡️ The Bottom Line
Patch Tuesday is no longer just a routine maintenance task; it is a critical defense mechanism. With six zero-days currently being exploited in the wild, the risk of a severe breach is significantly elevated.
Whether you are managing an enterprise network or just using your personal PC, the directive is clear: Do not delay. Update your systems immediately.
Stay secure, stay updated. For more deep dives into cybersecurity threats, vulnerabilities, and tech news, follow the Bug Mohol publication.
Orginal Post : https://www.bugmohol.com/2026/02/microsoft-security-updates-6-zero-day-fixes.html
메타데이터
- post_id
- 2b983a83009e
- slug
- critical-alert-microsoft-patches-6-actively-exploited-zero-days-in-massive-59-flaw-security-update-2b983a83009e
- url
- https://medium.com/@bugmohol/critical-alert-microsoft-patches-6-actively-exploited-zero-days-in-massive-59-flaw-security-update-2b983a83009e
- canonical_url
- https://medium.com/@bugmohol/critical-alert-microsoft-patches-6-actively-exploited-zero-days-in-massive-59-flaw-security-update-2b983a83009e
- author_url
- https://medium.com/@bugmohol
- status
- ok
- fetched_at
- 2026-06-17 12:55:42