
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21510 is a protection mechanism failure (CWE-693) in Windows Shell that allows an unauthenticated remote attacker to bypass a security feature — specifically Windows SmartScreen — when a user interacts with a malicious link or file. Disclosed and patched on February 10, 2026, as part of Microsoft's February Patch Tuesday, it affects a broad range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), and Windows Server 2012 through 2025. It carries a CVSS v3.1 base score of 8.8 (High) and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on the same day it was patched (Microsoft MSRC, CISA KEV).
The vulnerability is rooted in a protection mechanism failure (CWE-693) within Windows Shell, where the SmartScreen security feature can be bypassed when processing specially crafted shortcut files (LNK) or malicious links. The attack vector is network-based and requires user interaction — typically a single click on a malicious link or file — but requires no privileges. A related incomplete patch later led to a follow-on zero-day (CVE-2026-32202), which enabled zero-click NTLM credential coercion, indicating the original fix did not fully address the underlying Shell parsing logic (Microsoft MSRC, SecurityWeek, Tenable). A proof-of-concept was published on GitHub within days of disclosure (PoC GitHub).
Successful exploitation allows an attacker to bypass Windows SmartScreen and related security prompts, enabling delivery and execution of malicious payloads without the usual user warnings. The CVSS scoring reflects high impact to confidentiality, integrity, and availability, meaning a successful attack can result in full system compromise, unauthorized data access, and potential for lateral movement within a network. The vulnerability has been leveraged for NTLM credential theft and remote code execution in observed campaigns, affecting all major Windows desktop and server platforms (CISA KEV, Proofpoint, Rapid7).
explorer.exe or shell-related processes.cmd.exe, powershell.exe, mshta.exe, or other LOLBins as child processes of Windows Shell (explorer.exe) without user-initiated context.Microsoft released patches on February 10, 2026, as part of the February Patch Tuesday cumulative updates. Affected versions and their fixed build numbers include: Windows 10 21H2/22H2 (build 10.0.19044/19045.6937), Windows 11 23H2 (build 10.0.22631.6649), Windows 11 24H2 (build 10.0.26100.7781), Windows 11 25H2 (build 10.0.26200.7781), Windows Server 2016 (build 10.0.14393.8868), Windows Server 2019 (build 10.0.17763.8389), Windows Server 2022 (build 10.0.20348.4711), Windows Server 2022 23H2 (build 10.0.25398.2149), and Windows Server 2025 (build 10.0.26100.32313) (Microsoft MSRC). Additionally, 0patch released micropatches for systems where the official patch was unavailable or incomplete (0patch Blog). Organizations should apply the February 2026 cumulative updates immediately, prioritize internet-facing and user-facing systems, and train users to be cautious of unsolicited links and file attachments.
The vulnerability received significant attention from the security community given its active exploitation status at disclosure. Forbes, TechCrunch, The Register, and BleepingComputer all covered the February Patch Tuesday release, highlighting CVE-2026-21510 as one of six actively exploited zero-days (Forbes, The Register). Tenable's Satnam Narang specifically called out CVE-2026-21510 in expert commentary on the February Patch Tuesday (Tenable). Later in April 2026, SecurityWeek and Help Net Security reported that Microsoft's original patch was incomplete, leading to a related zero-click vulnerability (CVE-2026-32202) actively exploited by APT28 (SecurityWeek, Help Net Security). The Emerging Threats community released detection rules on the same day as the patch, reflecting the urgency of the threat.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."