February 2026 Patch Tuesday: what Security and IT teams should prioritise
February 2026 Patch Tuesday is now available in the canonical BlackTree Patch Intelligence catalogue. The current bounded cohort covers Microsoft, Adobe and SAP. This is not a claim of unlimited vendor coverage.
The operational queue contains 85 approved patch records linked to 131 unique CVEs. BlackTree currently marks 18 records for an accelerated or out-of-band assessment. BlackTree urgency is separate from vendor severity, CVSS and EPSS.
Security teams should start with confirmed exploitation and exposed control-plane systems. IT administrators should then review applicability, prerequisites, restart impact, sequencing, known issues and rollback guidance on each patch detail page.
Most important Microsoft patches this month
The following fixes deserve early attention based on confirmed exploitation, public disclosure, attack path and technical impact. Applicability still depends on the products and roles deployed in each environment.
- CVE-2026-21513: MSHTML Framework Security Feature Bypass Vulnerability Microsoft marked exploitation as detected when the update shipped. Its CVSS vector describes a network attack that does not require prior privileges. Important, CVSS 8.8.
- CVE-2026-21510: Windows Shell Security Feature Bypass Vulnerability Microsoft marked exploitation as detected when the update shipped. Its CVSS vector describes a network attack that does not require prior privileges. Important, CVSS 8.8.
- CVE-2026-21514: Microsoft Word Security Feature Bypass Vulnerability Microsoft marked exploitation as detected when the update shipped. Important, CVSS 7.8.
- CVE-2026-21519: Desktop Window Manager Elevation of Privilege Vulnerability Microsoft marked exploitation as detected when the update shipped. This is most relevant after an attacker has already gained a foothold on a Windows system. Important, CVSS 7.8.
Open the canonical February 2026 Patch Tuesday action queue on cve.blacktree.nl.
Patch details and exploitation assessments were checked against the Microsoft Security Update Guide release data for February 2026.
Editorial article generated from approved catalogue data. Recheck the canonical cycle for later vendor revisions or BlackTree corrections.
Update, 1 September 2026: three February fixes later joined the exploited queue
The original priority list omitted three vulnerabilities that now belong in the February remediation queue because CISA records exploitation in the wild.
- CVE-2026-21509 is a Microsoft Office security-feature bypass. Microsoft published the advisory on 26 January, and CISA added it to KEV the same day.
- CVE-2026-21525 is a NULL-pointer dereference in Windows Remote Access Connection Manager that can let a local unauthorised attacker cause denial of service.
- CVE-2026-21533 is an improper privilege-management flaw in Windows Remote Desktop Services that can let an authorised local attacker elevate privileges.
The February cumulative updates address the Windows issues. Office installations should be checked against Microsoft’s applicable fixed build or supported release. Current exploitation evidence places these three items ahead of unexploited backlog entries with higher numerical scores.
Primary sources: Microsoft Security Response Center advisories for CVE-2026-21509, CVE-2026-21525 and CVE-2026-21533, plus the CISA KEV catalogue.


