logo

Windows Shell Security Feature 0-Day Vulnerability Let Attackers Bypass Authentication

ID: 3c558eef-6710-5d48-8625-ee015323f68e

STIX ID: report--3c558eef-6710-5d48-8625-ee015323f68e

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-02-11

Date Updated: 2026-04-21

Author: Abinaya

...
...

Microsoft issued Patch Tuesday updates addressing CVE-2026-21510, a Windows Shell "Security Feature Bypass" zero-day (CVSS 8.8) actively exploited in the wild; specially crafted shortcut/link files can evade SmartScreen and Mark of the Web checks, enabling immediate execution without user consent—apply February 10, 2026 updates and avoid opening unknown links or shortcut files until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.