Patch Tuesday: February 2026 (Expel’s version)
ID: e90dfa07-5053-5daf-bdf9-4c050143f006
STIX ID: report--e90dfa07-5053-5daf-bdf9-4c050143f006
Feed Name: Expel Blog
**Patch Tuesday — February 10, 2026:** Microsoft released fixes for 59 CVEs, including six actively exploited zero-days now listed in CISA's KEV; the report highlights three high-priority flaws (Windows Shell SFB CVE-2026-21510, MSHTML SFB CVE-2026-21513, and RDS privilege escalation CVE-2026-21533) and urges immediate patching. It also analyzes NTLM's longstanding weaknesses and outlines Microsoft's plan to disable NTLM by default in 2026 with recommended phases for auditing, hardening (SMB signing, EPA), and remediation or migration to Kerberos/modern identity providers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
