February 2026 Patch TuesdayKB5075897Out-of-band action

Microsoft · KB5075897

Linked CVE review

Deploy Microsoft Windows security update KB5075897

Linked CVEs
28
Confirmed exploited
5
PoC or lab evidence
0
Maximum CVSS
8.8
Evidence is kept separate

Confirmed exploitation, public exploit material, EPSS probability and CVSS severity answer different questions. “No confirmation recorded” means the checked sources do not currently confirm exploitation. It is not proof that exploitation has not occurred.

Reset
28 of 28 linked CVEs shown
Confirmed exploitedCVSS above 9.0
CVE and descriptionSeverityExploit realityForecast and accessRemediation
CVE-2026-21510 Immediate evidence
Microsoft Windows Shell Protection Mechanism Failure Vulnerability

Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.

8.8 · CVSS 3.1 · HighSource: CNAConfirmed in the wildCISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-02-10.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 24.5% · 97.8th percentileForecast date: 2026-10-08NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionPatch nowCISA confirms exploitation in the wild and lists 2026-03-03 as the remediation due date.Mitigation available. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21513 Immediate evidence
Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability

Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.

8.8 · CVSS 3.1 · HighSource: CNAConfirmed in the wildCISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-02-10.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 15.9% · 96.8th percentileForecast date: 2026-10-08NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionPatch nowCISA confirms exploitation in the wild and lists 2026-03-03 as the remediation due date.Mitigation available. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21525 Immediate evidence
Microsoft Windows NULL Pointer Dereference Vulnerability

Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally.

6.2 · CVSS 3.1 · MediumSource: CNAConfirmed in the wildCISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-02-10.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 4.87% · 91.8th percentileForecast date: 2026-10-08LOCAL · LOW complexity · NONE privileges · NONE user interactionPatch nowCISA confirms exploitation in the wild and lists 2026-03-03 as the remediation due date.Mitigation available. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21533 Immediate evidence
Microsoft Windows Improper Privilege Management Vulnerability

Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally.

7.8 · CVSS 3.1 · HighSource: CNAConfirmed in the wildCISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-02-10.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 4.18% · 90.7th percentileForecast date: 2026-10-08LOCAL · LOW complexity · LOW privileges · NONE user interactionPatch nowCISA confirms exploitation in the wild and lists 2026-03-03 as the remediation due date.Mitigation available. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21519 Immediate evidence
Microsoft Windows Type Confusion Vulnerability

Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.

7.8 · CVSS 3.1 · HighSource: CNAConfirmed in the wildCISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-02-10.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 2.50% · 84.2th percentileForecast date: 2026-10-08LOCAL · LOW complexity · LOW privileges · NONE user interactionPatch nowCISA confirms exploitation in the wild and lists 2026-03-03 as the remediation due date.Mitigation available. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21238 Scheduled assessment
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

7.8 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 3.38% · 88.4th percentileForecast date: 2026-10-08LOCAL · LOW complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21241 Scheduled assessment
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

7.0 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 2.60% · 84.9th percentileForecast date: 2026-10-08LOCAL · HIGH complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21231 Scheduled assessment
Windows Kernel Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.8 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 2.58% · 84.7th percentileForecast date: 2026-10-08LOCAL · HIGH complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-20846 Scheduled assessment
GDI+ Denial of Service Vulnerability

Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.

7.5 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 1.44% · 72.4th percentileForecast date: 2026-10-08NETWORK · LOW complexity · NONE privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21243 Scheduled assessment
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

7.5 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 1.44% · 72.4th percentileForecast date: 2026-10-08NETWORK · LOW complexity · NONE privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21244 Scheduled assessment
Windows Hyper-V Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

7.3 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 1.34% · 70.4th percentileForecast date: 2026-10-08LOCAL · LOW complexity · LOW privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21248 Scheduled assessment
Windows Hyper-V Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

7.3 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 1.34% · 70.4th percentileForecast date: 2026-10-08LOCAL · LOW complexity · LOW privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21250 Scheduled assessment
Windows HTTP.sys Elevation of Privilege Vulnerability

Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

7.8 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 1.12% · 65.2th percentileForecast date: 2026-10-08LOCAL · LOW complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21253 Scheduled assessment
Mailslot File System Elevation of Privilege Vulnerability

Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.

7.0 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.81% · 55.6th percentileForecast date: 2026-10-08LOCAL · HIGH complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21247 Scheduled assessment
Windows Hyper-V Remote Code Execution Vulnerability

Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.

7.3 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.59% · 46.5th percentileForecast date: 2026-10-08LOCAL · LOW complexity · LOW privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21508 Scheduled assessment
Windows Storage Elevation of Privilege Vulnerability

Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally.

7.0 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.45% · 37.5th percentileForecast date: 2026-10-08LOCAL · HIGH complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21246 Scheduled assessment
Windows Graphics Component Elevation of Privilege Vulnerability

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

7.8 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.45% · 37.1th percentileForecast date: 2026-10-08LOCAL · LOW complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21232 Scheduled assessment
Windows HTTP.sys Elevation of Privilege Vulnerability

Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

7.8 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.45% · 37.0th percentileForecast date: 2026-10-08LOCAL · LOW complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21239 Scheduled assessment
Windows Kernel Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.8 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.45% · 37.0th percentileForecast date: 2026-10-08LOCAL · LOW complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21236 Scheduled assessment
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

7.8 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.45% · 36.7th percentileForecast date: 2026-10-08LOCAL · LOW complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21251 Scheduled assessment
Cluster Client Failover (CCF) Elevation of Privilege Vulnerability

Use after free in Windows Cluster Client Failover allows an authorized attacker to elevate privileges locally.

7.8 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.45% · 36.7th percentileForecast date: 2026-10-08LOCAL · LOW complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21255 Scheduled assessment
Windows Hyper-V Security Feature Bypass Vulnerability

Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally.

8.8 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.38% · 30.3th percentileForecast date: 2026-10-08LOCAL · LOW complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21242 Scheduled assessment
Windows Subsystem for Linux Elevation of Privilege Vulnerability

Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

7.0 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.36% · 28.1th percentileForecast date: 2026-10-08LOCAL · HIGH complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21240 Scheduled assessment
Windows HTTP.sys Elevation of Privilege Vulnerability

Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

7.8 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.28% · 19.0th percentileForecast date: 2026-10-08LOCAL · LOW complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21234 Scheduled assessment
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.

7.0 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.28% · 18.3th percentileForecast date: 2026-10-08LOCAL · HIGH complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21237 Scheduled assessment
Windows Subsystem for Linux Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

7.0 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.28% · 18.3th percentileForecast date: 2026-10-08LOCAL · HIGH complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21249 Elevated EPSS forecast
Windows NTLM Spoofing Vulnerability

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.

3.3 · CVSS 3.1 · LowSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 11.5% · 95.9th percentileForecast date: 2026-10-08LOCAL · LOW complexity · NONE privileges · REQUIRED user interactionScheduledLow technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-21222 Scheduled assessment
Windows Kernel Information Disclosure Vulnerability

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

5.5 · CVSS 3.1 · MediumSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.61% · 47.8th percentileForecast date: 2026-10-08LOCAL · LOW complexity · LOW privileges · NONE user interactionScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.