Vulnerability Management, Patch/Configuration Management

Half a dozen exploited zero-days fixed by Microsoft

Security Affairs reports that Microsoft has addressed six zero-day flaws that have been under attack as part of this month's Patch Tuesday release.

Three of the actively exploited vulnerabilities have already been publicized, including the high-severity Windows SmartScreen and Shell prompt bypass bug, tracked as CVE-2026-21510; the high-severity Internet Explorer security control bypass issue, tracked as CVE-2026-21513; and the high-severity Microsoft 365 and Office OLE security bypass defect, tracked as CVE-2026-21514.

Microsoft also fixed the high-severity Windows Desktop Window Manager flaw, tracked as CVE-2026-21519, which could be exploited for local privilege escalation; the medium-severity Windows Remote Access Connection Manager vulnerability, tracked as CVE-2026-21525, which could be harnessed for denial-of-service; and the high-severity Windows Remote Desktop Services issue, tracked as CVE-2026-21533, which could allow elevation to SYSTEM privileges.

In total, Microsoft patched 58 new security flaws across WSL, Hyper-V, Azure, Exchange, Edge, Office, Windows, and other components. The total comes to 62 CVEs if including third-party updates.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds