Summary
Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. An attacker must trick a user into opening a specially crafted link or shortcut file, after which Windows may fail to show the expected SmartScreen or shell warning. That can let attacker-controlled content run without the normal user consent prompt and may lead to compromise of the affected system.
Why Planned Fix?
4/6Exploitation Details
Execute attacker-controlled content on the victim system with the user's privileges.
RCE (Remote Code Execution)Affected Software
| Product | Affected Versions |
|---|---|
| Windows 10 | 1607, 1809, 21H2, 22H2 and earlier builds before the February 2026 security update |
| Windows 11 | 23H2, 24H2, 25H2 and earlier builds before the February 2026 security update |
| Windows Server | 2012, 2012 R2, 2016, 2019, 2022, 2022 23H2, 2025 and earlier builds before the February 2026 security update |
Windows is Microsoft's desktop and server operating system family. Windows Shell provides the graphical shell, file handling, and shortcut/link launch behavior used by Explorer and related components.
Affected ComponentWindows Shell link and shortcut handling, including SmartScreen and shell security prompt enforcement.
Windows Shell link and shortcut handling, including SmartScreen and shell security prompt enforcement.
Not available
Not available
Install Microsoft’s February 10, 2026 Windows security update or later for the affected Windows 10, Windows 11, and Windows Server branches. Microsoft’s advisory lists the fixed build levels for each supported release.
Install Microsoft’s February 10, 2026 Windows security update or later for the affected Windows 10, Windows 11, and Windows Server branches. Microsoft’s advisory lists the fixed build levels for each supported release.
Probability of exploitation in the next 30 days
Worse than 87% of all CVEs
No known threat actors
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Affected Software (CPE) (23)
- •cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*
- •cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
- •cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*
- •cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
- •cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*
- •cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*
- •cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*
- •cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*
- •cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*
- •cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*
- •cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*
- •cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*
- •cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
- •cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
- •cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
- •cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
- •cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Sources
| Source | Article |
|---|---|
| nvd.nist.gov | CVE-2026-21510 Detail |
| msrc.microsoft.com | CVE-2026-21510 Security Update Guide |
| www.cisa.gov | Known Exploited Vulnerabilities Catalog |
| www.bleepingcomputer.com | Microsoft February 2026 Patch Tuesday fixes 6 zero-days, 58 flaws |
| www.tenable.com | CVE-2026-21510 |
| www.qualys.com | Microsoft Security Bulletins: February 2026 |
Priority History
Initial analysis