Safeguard
Vulnerability Analysis

Five More Microsoft CVEs Confirmed Exploited, Four on the Same Day

MSHTML, Windows Shell, Desktop Window Manager, and Office Word all produced confirmed-exploited bugs landing on CISA's KEV catalogue within a fifteen-day window in early 2026.

Safeguard Research Team
5 min read

Five more Microsoft vulnerabilities were confirmed exploited within a single fifteen-day window spanning late January and mid-February 2026 — four of them added to CISA's Known Exploited Vulnerabilities catalogue on the exact same day. This is an additional Microsoft finding distinct from the WSUS, Configuration Manager, SharePoint, Exchange, Defender, and broader Windows privilege-escalation clusters already documented elsewhere in this series: these five span MSHTML, Windows Shell, Desktop Window Manager, and Office Word, all confirmed exploited in near lockstep.

CVECVSSComponentAdded to KEV
CVE-2026-215138.8MSHTML Framework10 Feb 2026
CVE-2026-215108.8Windows Shell10 Feb 2026
CVE-2026-215197.8Desktop Window Manager10 Feb 2026
CVE-2026-215147.8Office Word10 Feb 2026
CVE-2026-215097.8Office (general)26 Jan 2026

Why four CVEs landing on one KEV date, from three different products, is the real story

CISA rarely adds four unrelated CVEs from a single vendor on the same calendar day unless that vendor's own disclosure cadence produced them together — which is exactly what a monthly Patch Tuesday release does. CVE-2026-21513, CVE-2026-21510, CVE-2026-21519, and CVE-2026-21514 were all published to NVD within roughly ninety seconds of each other on 10 February 2026, a pattern that only happens when a vendor batches its advisories into one scheduled release. Microsoft's February 2026 update cycle evidently shipped fixes for at least four actively exploited vulnerabilities simultaneously, and CISA's KEV team confirmed exploitation for all four together. That means an organization that runs Patch Tuesday updates on a monthly cadence, rather than accelerating for actively-exploited findings specifically, was carrying four confirmed-exploited bugs across its Windows and Office estate for however long its internal patch window took to close.

CVE-2026-21509 — a closely related Office security-feature-bypass bug sharing the same underlying weakness class — was confirmed exploited two weeks earlier, on 26 January 2026, and carries a notable detail in CISA's own guidance: some of the affected Office versions "could be end-of-life (EoL) and/or end-of-service (EoS)," with CISA explicitly recommending organizations "discontinue use and/or transition to a supported version" for products no longer receiving full fixes. Microsoft's own guidance splits the remediation path by version — Office 2021 gets a final mitigation, while Office 2016 and Office 2019 get only an interim one pending a later patch. That is a meaningfully different remediation burden depending on which Office version an organization still runs, and it is easy to miss if a patch-management process treats "Office" as a single product rather than tracking version-specific advisories.

The shared weakness class across three of these five

CVE-2026-21513, CVE-2026-21510, and CVE-2026-21509 are all classified under protection-mechanism-failure weakness categories (CWE-693 for the first two, CWE-807 — reliance on untrusted inputs in a security decision — for the Office pair). In plain terms, these are not memory-corruption bugs that crash a process; they are logic bugs where a component makes a security decision based on input it should not have trusted, letting an attacker slip past a check that was supposed to stop them. MSHTML and Windows Shell both require user interaction (CVSS UI:R) to trigger, meaning the practical attack path runs through a user opening a file or following a link — the same social-engineering-dependent delivery model behind a large share of real-world Windows exploitation, regardless of which specific component ends up compromised.

CVE-2026-21519, by contrast, is a type confusion bug (CWE-843) in Desktop Window Manager requiring local access and low privileges already in hand — consistent with the local-elevation pattern that recurs constantly across Windows KEV entries: an attacker rarely needs remote code execution from zero when a phishing-delivered payload plus a local elevation bug accomplishes the same end state with less engineering effort.

What to check this week

Confirm the February 2026 cumulative update is applied across every Windows and Office endpoint, not just servers — MSHTML and Windows Shell bugs affect any workstation where a user can open a document or browse a network share, which is nearly the entire fleet.

Audit which Office version each endpoint is running before assuming CVE-2026-21509 is closed. The interim-versus-final mitigation split between Office 2021 and the 2016/2019 lines means "we patched Office" is not a single, verifiable statement — verify by exact version.

Flag any Office 2016 or Office 2019 deployment for a lifecycle review. CISA's own note that affected versions may be EoL/EoS is a signal that patching alone will not close every future finding in this product line; a version upgrade plan belongs on the same timeline as this specific patch.

Treat the four same-day KEV additions as one remediation ticket, not four, since they trace to the same monthly release and very likely reached affected endpoints through the same update mechanism.

A closing note on patch-cycle timing versus exploitation timing

The gap between a scheduled monthly patch cycle and the moment CISA confirms in-the-wild exploitation is not fixed — sometimes it is measured in days, sometimes these findings surface after exploitation has already been underway for a stretch of the patch-cycle interval. Four confirmed-exploited CVEs surfacing on one release date is a reminder that "monthly patching" and "patching everything CISA has confirmed exploited" are not automatically the same practice, and an organization's process should distinguish between the two rather than assuming the regular cadence alone closes every actively-exploited gap.

How Safeguard helps

Safeguard's continuous inventory tracks exact Windows and Office build and version numbers across the fleet, not just "patched" or "unpatched" at the product level — which is precisely the granularity needed to confirm whether an Office 2016 install actually received its interim mitigation for CVE-2026-21509, or whether a workstation missed the February cumulative update that closed the other four confirmed-exploited findings in this cluster.

Never miss an update

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.