Full Report
Microsoft has released its monthly security update for February 2026, which includes 55 vulnerabilities affecting a range of products, including one (CVE-2025-59498) that Microsoft marked as “Critical”.
Analysis Summary
Based on the provided context from the February 2026 Patch Tuesday update summary, here is the focused vulnerability breakdown:
# Vulnerability: Critical Elevation of Privilege in Microsoft ACI Containers
## CVE Details
- CVE ID: CVE-2026-21522
- CVSS Score: 6.7 (Critical) - *Note: Microsoft marked this "Critical," but the provided CVSS score of 6.7 typically corresponds to **High** severity.*
- CWE: Not available in context.
## Affected Systems
- Products: Microsoft ACI Confidential Containers
- Versions: Not specified.
- Configurations: Not specified.
## Vulnerability Description
This is a critical Elevation of Privilege (EoP) vulnerability. Successful exploitation could enable an authorized attacker to escalate privileges on affected systems running Microsoft ACI Confidential Containers.
## Exploitation
- Status: Not publicly disclosed, not listed as actively exploited.
- Complexity: Not specified.
- Attack Vector: Not specified (likely internal or via management plane access, given the product context).
## Impact
- Confidentiality: Not specified.
- Integrity: Not specified.
- Availability: Not specified.
## Remediation
### Patches
- Patches are available as part of the February 2026 Microsoft Security Update release. (Specific KB/version numbers not provided in the summary text.)
### Workarounds
- No workarounds were explicitly listed in the summary text.
## Detection
- No specific IOCs or Talos signatures related to CVE-2026-21522 were detailed in the summary text.
## References
- [Vendor advisory](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-21522)
- [General Article](https://blog.talosintelligence.com/2026/02/microsoft-patch-tuesday-february-2026.html)
---
# Vulnerability: Critical Information Disclosure in Microsoft ACI Containers
## CVE Details
- CVE ID: CVE-2026-23655
- CVSS Score: 6.5 (Critical) - *Note: Microsoft marked this "Critical," but the provided CVSS score of 6.5 typically corresponds to **Medium** severity.*
- CWE: Not available in context.
## Affected Systems
- Products: Microsoft ACI Confidential Containers
- Versions: Not specified.
- Configurations: Not specified.
## Vulnerability Description
This is a critical Information Disclosure vulnerability. Successful exploitation could enable an authorized attacker to disclose sensitive information, including secret tokens and encryption keys, on affected systems.
## Exploitation
- Status: Not publicly disclosed, not listed as actively exploited.
- Complexity: Not specified.
- Attack Vector: Not specified.
## Impact
- Confidentiality: High (Disclosure of tokens/keys).
- Integrity: Not specified.
- Availability: Not specified.
## Remediation
### Patches
- Patches are available as part of the February 2026 Microsoft Security Update release. (Specific KB/version numbers not provided in the summary text.)
### Workarounds
- No workarounds were explicitly listed in the summary text.
## Detection
- No specific IOCs or Talos signatures related to CVE-2026-23655 were detailed in the summary text.
## References
- [Vendor advisory](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-23655)
- [General Article](https://blog.talosintelligence.com/2026/02/microsoft-patch-tuesday-february-2026.html)
---
***Summary Note on Other Disclosed/Exploited Flaws:***
The overall update contained **59 vulnerabilities**. The following vulnerabilities were explicitly listed as **Publicly Disclosed** or **Actively Exploited**:
| CVE ID | Severity/Status Note | Vulnerability Type | Affected Product Snippet | Exploitation Status |
| :--- | :--- | :--- | :--- | :--- |
| **CVE-2026-21510** | Publicly Disclosed | Security Feature Bypass | Windows Shell | Requires user interaction (malicious file) to bypass SmartScreen/Shell prompts (Unauthenticated attacker). |
| **CVE-2026-21513** | Important (CVSS 8.8) & Publicly Disclosed | Security Feature Bypass | MSHTML Framework | Requires user interaction (crafted HTML/LNK file) to bypass features and achieve Code Execution. |
| **CVE-2026-21514** | Publicly Disclosed | Security Feature Bypass (Reliance on Untrusted Input) | Microsoft Office Word | Requires user interaction (malicious document); bypasses OLE mitigation. |
| **CVE-2026-21519** | Important (Implied) | Type Confusion | Desktop Window Manager (DWM) | Local, authenticated attacker to escalate to SYSTEM level access. |
| **CVE-2026-21533** | Important (Implied) | Elevation of Privilege | Windows Remote Desktop Services | Local attacker to escalate to SYSTEM level privileges via improper privilege management. |
| **CVE-2026-21525** | Moderate (CVSS 6.2) & Actively Exploited | Denial of Service (Null Pointer Dereference) | Windows Remote Access Connection Manager | Network vulnerability leading to DoS. *This is the only "Moderate" flaw noted as actively exploited.* |
| **CVE-2026-21228** | Important (Implied) | Improper Certificate Validation (RCE) | Azure Local | Network attack, potential scope change across tenants via intercepting unsecured communication. |
| **CVE-2026-20841** | Important (Implied) | Remote Code Execution (RCE) | Microsoft Notepad | Details limited. |
| CVE-2026-21244, CVE-2026-21248 | Important (Implied) | Arbitrary Code Execution (ACE) | Windows Hyper-V | Local exploitation required, often via opening malicious Office files. |
| CVE-2026-21516 | Important (Implied) | Arbitrary Code Execution (ACE) | GitHub Copilot for JetBrains | Locally exploitable, requires existing code execution. |
| CVE-2026-21523 | Important (Implied) | RCE | GitHub Copilot | Network attack vector indicated, limited details. |
| CVE-2026-21256 | Important (Implied) | Command Injection | GitHub Copilot / VS Code | Remote Code Execution due to improper handling of special characters. |
**Active Exploitation Note:** Microsoft explicitly reported **five vulnerabilities rated as "Important"** were being actively exploited, plus the one "Moderate" vulnerability (CVE-2026-21525).
**Detection:** Talos released a new Snort ruleset covering several vulnerabilities: Snort 2 rules **65895-65900, 65902, 65903, 65906-65911, 65913, 65914, 65923, 65924**. Snort 3 rules **301395-301403** are also available. Cisco Firewall customers must update their SRU.