CVE-2026-21510
vulnerability analysis and mitigation

Overview

CVE-2026-21510 is a protection mechanism failure (CWE-693) in Windows Shell that allows an unauthenticated remote attacker to bypass a security feature — specifically Windows SmartScreen — when a user interacts with a malicious link or file. Disclosed and patched on February 10, 2026, as part of Microsoft's February Patch Tuesday, it affects a broad range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), and Windows Server 2012 through 2025. It carries a CVSS v3.1 base score of 8.8 (High) and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on the same day it was patched (Microsoft MSRC, CISA KEV).

Technical details

The vulnerability is rooted in a protection mechanism failure (CWE-693) within Windows Shell, where the SmartScreen security feature can be bypassed when processing specially crafted shortcut files (LNK) or malicious links. The attack vector is network-based and requires user interaction — typically a single click on a malicious link or file — but requires no privileges. A related incomplete patch later led to a follow-on zero-day (CVE-2026-32202), which enabled zero-click NTLM credential coercion, indicating the original fix did not fully address the underlying Shell parsing logic (Microsoft MSRC, SecurityWeek, Tenable). A proof-of-concept was published on GitHub within days of disclosure (PoC GitHub).

Impact

Successful exploitation allows an attacker to bypass Windows SmartScreen and related security prompts, enabling delivery and execution of malicious payloads without the usual user warnings. The CVSS scoring reflects high impact to confidentiality, integrity, and availability, meaning a successful attack can result in full system compromise, unauthorized data access, and potential for lateral movement within a network. The vulnerability has been leveraged for NTLM credential theft and remote code execution in observed campaigns, affecting all major Windows desktop and server platforms (CISA KEV, Proofpoint, Rapid7).

Exploitation steps

  1. Reconnaissance: Identify targets running unpatched Windows systems (Windows 10, 11, or Server editions prior to February 2026 cumulative updates) using open-source intelligence or network scanning.
  2. Craft malicious payload: Create a specially crafted LNK (shortcut) file or a malicious URL/web link that exploits the Windows Shell protection mechanism failure to bypass SmartScreen validation.
  3. Deliver payload: Distribute the malicious LNK file or link via phishing email, spear-phishing, or malicious website — requiring only a single user click to trigger exploitation.
  4. Bypass SmartScreen: When the victim opens the link or file, Windows Shell fails to properly invoke SmartScreen protections, allowing the payload to execute without security warnings.
  5. Achieve objective: Depending on the payload, the attacker can execute arbitrary code, steal NTLM credentials (via coercion to an attacker-controlled server), or establish persistence on the compromised host for lateral movement (Microsoft MSRC, SecurityWeek, Proofpoint).

Indicators of compromise

  • Network: Outbound SMB or HTTP connections to unknown/attacker-controlled servers immediately following a user opening a LNK file or clicking a link; NTLM authentication attempts to external IPs (indicative of credential coercion).
  • File System: Unexpected LNK files in user download directories, temp folders, or email attachment staging areas with unusual target paths or embedded UNC paths pointing to external servers.
  • Logs: Windows Security event logs showing SmartScreen bypass events or suppressed Mark-of-the-Web (MotW) warnings; process creation events (Event ID 4688) showing unusual child processes spawned from explorer.exe or shell-related processes.
  • Process: Unexpected execution of cmd.exe, powershell.exe, mshta.exe, or other LOLBins as child processes of Windows Shell (explorer.exe) without user-initiated context.
  • Emerging Threats: Suricata/Snort rules were released by Emerging Threats on February 10, 2026 (ruleset v11122) to detect exploitation attempts (Emerging Threats).

Mitigation and workarounds

Microsoft released patches on February 10, 2026, as part of the February Patch Tuesday cumulative updates. Affected versions and their fixed build numbers include: Windows 10 21H2/22H2 (build 10.0.19044/19045.6937), Windows 11 23H2 (build 10.0.22631.6649), Windows 11 24H2 (build 10.0.26100.7781), Windows 11 25H2 (build 10.0.26200.7781), Windows Server 2016 (build 10.0.14393.8868), Windows Server 2019 (build 10.0.17763.8389), Windows Server 2022 (build 10.0.20348.4711), Windows Server 2022 23H2 (build 10.0.25398.2149), and Windows Server 2025 (build 10.0.26100.32313) (Microsoft MSRC). Additionally, 0patch released micropatches for systems where the official patch was unavailable or incomplete (0patch Blog). Organizations should apply the February 2026 cumulative updates immediately, prioritize internet-facing and user-facing systems, and train users to be cautious of unsolicited links and file attachments.

Community reactions

The vulnerability received significant attention from the security community given its active exploitation status at disclosure. Forbes, TechCrunch, The Register, and BleepingComputer all covered the February Patch Tuesday release, highlighting CVE-2026-21510 as one of six actively exploited zero-days (Forbes, The Register). Tenable's Satnam Narang specifically called out CVE-2026-21510 in expert commentary on the February Patch Tuesday (Tenable). Later in April 2026, SecurityWeek and Help Net Security reported that Microsoft's original patch was incomplete, leading to a related zero-click vulnerability (CVE-2026-32202) actively exploited by APT28 (SecurityWeek, Help Net Security). The Emerging Threats community released detection rules on the same day as the patch, reflecting the urgency of the threat.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management