Patch Tuesday cycleFebruary 2026 Patch TuesdayComplete

Canonical Patch Tuesday catalogue

February 2026 Patch Tuesday catalogue.

Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 85 operational patch records link 131 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.

85Patch recordsStable operational entries, not CVE duplicates
131Linked unique CVEsEvery CVE opens in BlackTree CVE Intelligence
18Accelerated actionsOut-of-band action
2Revised entriesCanonical history remains visible

February 2026 Patch Tuesday

Patch catalogue

Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.

Hide update groups
No groups hidden

Select every group you want removed from this view, its shared URL and its filtered exports.

Adobe
Microsoft
SAP
Several vendor and product groups can be hidden together.
Additional filtersProduct, platform, exploitation, restart, issues, date and cycle state
Reset filters
85 matching recordsPage 1 of 5
Selected PDF report0 of 20 visible records selectedSelect up to 20 approved records. Filter-hidden selections remain selected until cleared.
AdobeUpdate Adobe Lightroom Classic to the fixed Adobe releaseAPSB26-06 · Updated 2026-02-10
Product and releaseAdobe Lightroom Classic15.1.1, 14.5.2 LTS
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB26-06 on Patch Tuesday for Adobe Lightroom Classic. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-06
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeReassess the updated Adobe Substance 3D Modeler Adobe releaseAPSB26-08 · Updated 2026-02-10
Product and releaseAdobe Substance 3D Modeler1.22.5
Review linked CVEs (6) No confirmed exploitation stated

Operational summary

Adobe updated APSB26-08 on Patch Tuesday for Adobe Substance 3D Modeler. The bulletin links 6 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-08
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (6)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Substance 3D Designer to the fixed Adobe releaseAPSB26-19 · Updated 2026-02-10
Product and releaseAdobe Substance 3D Designer15.1.2
Review linked CVEs (7) No confirmed exploitation stated

Operational summary

Adobe published APSB26-19 on Patch Tuesday for Adobe Substance 3D Designer. The bulletin links 7 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-19
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (7)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Substance 3D Modeler to the fixed Adobe releaseAPSB26-22 · Updated 2026-02-10
Product and releaseAdobe Substance 3D Modeler1.22.6
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB26-22 on Patch Tuesday for Adobe Substance 3D Modeler. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-22
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important; CVSS 5.5; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 5.5
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe DNG SDK to the fixed Adobe releaseAPSB26-23 · Updated 2026-02-10
Product and releaseAdobe DNG SDKDNG SDK 1.7.1 build 2471
Review linked CVEs (4) No confirmed exploitation stated

Operational summary

Adobe published APSB26-23 on Patch Tuesday for Adobe DNG SDK. The bulletin links 4 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-23
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (4)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Audition to the fixed Adobe releaseAPSB26-14 · Updated 2026-02-10
Product and releaseAdobe Audition25.6, 26.0
Review linked CVEs (6) No confirmed exploitation stated

Operational summary

Adobe published APSB26-14 on Patch Tuesday for Adobe Audition. The bulletin links 6 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-14
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (6)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe After Effects to the fixed Adobe releaseAPSB26-15 · Updated 2026-02-10
Product and releaseAdobe After Effects25.6.4, 26.0
Review linked CVEs (15) No confirmed exploitation stated

Operational summary

Adobe published APSB26-15 on Patch Tuesday for Adobe After Effects. The bulletin links 15 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-15
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe InDesign to the fixed Adobe releaseAPSB26-17 · Updated 2026-02-10
Product and releaseAdobe InDesignID21.2, ID20.5.2
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

Adobe published APSB26-17 on Patch Tuesday for Adobe InDesign. The bulletin links 3 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-17
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Substance 3D Stager to the fixed Adobe releaseAPSB26-20 · Updated 2026-02-10
Product and releaseAdobe Substance 3D Stager3.1.7
Review linked CVEs (5) No confirmed exploitation stated

Operational summary

Adobe published APSB26-20 on Patch Tuesday for Adobe Substance 3D Stager. The bulletin links 5 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-20
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (5)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Bridge to the fixed Adobe releaseAPSB26-21 · Updated 2026-02-10
Product and releaseAdobe Bridge15.1.4 (LTS), 16.0.2
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

Adobe published APSB26-21 on Patch Tuesday for Adobe Bridge. The bulletin links 2 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-21
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Apps update for Windows NotepadMSRC-2026-02-apps-release-notes · Updated 2026-02-10
Product and releaseWindows Notepad11.2512.26.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows Notepad.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-02-apps-release-notes
Platform
Apps
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure DevOps Server 2022MSRC-2026-02-azure-release-notes · Updated 2026-02-10
Product and releaseAzure DevOps Server 202220260204.3
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure DevOps Server 2022.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-02-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 6.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Microsoft ACI Confidential ContainersMSRC-2026-02-azure-release-notes · Updated 2026-02-10
Product and releaseMicrosoft ACI Confidential Containers1.2.8, 2.12
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft ACI Confidential Containers.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-02-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 6.7
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure IoT ExplorerMSRC-2026-02-azure-release-notes · Updated 2026-02-10
Product and releaseAzure IoT Explorer0.15.13
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure IoT Explorer.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-02-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 6.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure AI Language AuthoringMSRC-2026-02-azure-release-notes · Updated 2026-02-10
Product and releaseAzure AI Language Authoring1.0.0b4
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure AI Language Authoring.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-02-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 9.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure HDInsightMSRC-2026-02-azure-release-notes · Updated 2026-02-10
Product and releaseAzure HDInsight5.1
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure HDInsight.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-02-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 5.7
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure LocalMSRC-2026-02-azure-release-notes · Updated 2026-02-10
Product and releaseAzure Local2510.0.3002
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Local.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-02-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.1
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5077862KB5077862 · Updated 2026-02-10
Product and release.NET 10.0 installed on Linux, .NET 10.0 installed on Mac OS, .NET 10.0 installed on Windows10.0.3
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for .NET 10.0 installed on Linux, .NET 10.0 installed on Mac OS, .NET 10.0 installed on Windows.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5077862
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5077863KB5077863 · Updated 2026-02-10
Product and release.NET 8.0 installed on Linux, .NET 8.0 installed on Mac OS, .NET 8.0 installed on Windows8.0.24
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for .NET 8.0 installed on Linux, .NET 8.0 installed on Mac OS, .NET 8.0 installed on Windows.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5077863
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5077864KB5077864 · Updated 2026-02-10
Product and release.NET 9.0 installed on Linux, .NET 9.0 installed on Mac OS, .NET 9.0 installed on Windows9.0.13
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for .NET 9.0 installed on Linux, .NET 9.0 installed on Mac OS, .NET 9.0 installed on Windows.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5077864
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0