Windows Shell Zero-Day Vulnerability Allows Attackers to Bypass Authentication
ID: aad82fae-1271-5561-9694-5ee41aee5076
STIX ID: report--aad82fae-1271-5561-9694-5ee41aee5076
Feed Name: GBHackers
**Executive Summary:** Microsoft has warned of a critical Windows Shell Security Feature Bypass (CVE-2026-21510, CVSS 8.8) actively exploited in the wild that allows malicious shortcuts or links to execute without SmartScreen or Mark of the Web prompts; the flaw affects a broad range of Windows desktop and server releases and Microsoft/MSTIC and Google identified the issue, with patches available in the February 2026 updates — administrators should apply updates immediately and avoid untrusted shortcut/link files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
