Microsoft released security updates to fix several zero day vulnerabilities in Windows and in Office. The company says threat actors were already using some of these bugs to break into computers before patches were available. Security teams urge rapid updates because public details and active attacks increase the risk for users and organizations.

What was Patched
Microsoft rectified a number of critical flaws in its n February security update. Two defects are CVE 2026 21510 and CVE 2026 21513, which are the most urgent. The former targets the Windows shell and may allow attackers to get around SmartScreen, and other safety warnings on clicking a link or shortcut. The second exploits the MSHTML engine which is utilized by the legacy web content and can be exploited to evade the Office protections. Microsoft marked several of these issues as being exploited in the wild.
Experts and security teams note that Microsoft also patched other zero day flaws that were actively abused. Analysts listed CVE 2026 21514 which is an Office related bypass. Other fixes included privilege elevation and denial of service issues that had real world impact on targeted systems. Tracking lists show that this patch round addressed six zero day vulnerabilities in total.
How They Work
The user only has to do one-point click to initiate some of the attacks. Hackers are able to deceive their victims to log into a link or to open a created file. A single exploit may execute code post that single click and provide the attacker with access or avenue to install malware. Security researchers called a one click code execution bug rare and very risky. Public reports say that exploit details appeared before all systems were patched which can speed up more attacks.
MSHTML issues can turn ordinary Office content into an attack vector because Office can render older web content inside documents. The exchange of a crafted file in an email or a shared folder can make this attack work without many extra steps. The Windows shell bug can bypass user facing warnings so that a link looks safe when it is not. These behaviors explain why defenders must patch quickly and why companies should watch for signs of abuse.
How to Protect
Install Microsoft updates now on all Windows and Office machines. Run the normal update process and reboot when the system asks. Security teams should scan for signs of compromise and review logs for unexpected link clicks or file openings in the days before patching. Stricken email and web filters and caution users on suspicious links and unfamiliar attachments. Detection tools Endpoint detection tools should be used and backup maintained so that in case of a breach the systems can be restored.

Give special care to machines that still run legacy components or old apps that use MSHTML. Those systems can be more exposed because they rely on older web engines and on backward compatibility paths. Consider isolating such devices from critical networks until updates are applied. Maintain a plain and consistent plan for patch testing and deployment so that updates reach your users fast and safely.
The most basic precautions that can be taken by home consumers are updating windows, not clicking on unfamiliar links and not opening files that are sent by unfamiliar persons. Web links should use a modern browser and not the old compatibility mode. Make antivirus signatures up-to-date and monitor operating system notification bars on evidence of abuse. Most people reduce their risk as a result of quick actions.