Security Affairs reports that Microsoft has addressed six zero-day flaws that have been under attack as part of this month's Patch Tuesday release.Three of the actively exploited vulnerabilities have already been publicized, including the high-severity Windows SmartScreen and Shell prompt bypass bug, tracked as CVE-2026-21510; the high-severity Internet Explorer security control bypass issue, tracked as CVE-2026-21513; and the high-severity Microsoft 365 and Office OLE security bypass defect, tracked as CVE-2026-21514.Microsoft also fixed the high-severity Windows Desktop Window Manager flaw, tracked as CVE-2026-21519, which could be exploited for local privilege escalation; the medium-severity Windows Remote Access Connection Manager vulnerability, tracked as CVE-2026-21525, which could be harnessed for denial-of-service; and the high-severity Windows Remote Desktop Services issue, tracked as CVE-2026-21533, which could allow elevation to SYSTEM privileges.In total, Microsoft patched 58 new security flaws across WSL, Hyper-V, Azure, Exchange, Edge, Office, Windows, and other components. The total comes to 62 CVEs if including third-party updates.
Vulnerability Management, Patch/Configuration Management
Half a dozen exploited zero-days fixed by Microsoft

Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



