CVE detail
CVE-2026-21519
Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 23.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
9 source links · newest first
Microsoft’s February Patch Tuesday fixes 59 flaws—including six zero-days already under active attack. How bad are they?
newswww.malwarebytes.comFeb 11, 2026, 12:32 PMMicrosoft has plugged 50+ security holes on February 2026 Patch Tuesday, including six zero-day vulnerabilities exploited by attackers in the wild. The “security feature bypass” zero-days Among the zero-days fixed are three vulnerabilities that allow attackers to bypass a security feature. CVE-2026-21513 affects the MSHTML/Trident browser engine for the Microsoft Windows version of Internet Explorer, and CVE-2026-21514 affects Microsoft Word. The former can be exploited by attackers by convincing a user to open a malicious … More →
newswww.helpnetsecurity.comFeb 11, 2026, 12:06 PM- U.S. CISA adds Microsoft Office and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Office and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Microsoft Office and Microsoft Windows flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the catalog: This week, Microsoft Patch Tuesday security […]
newssecurityaffairs.comFeb 11, 2026, 7:37 AM - February 2026 Patch Tuesday: Six new and actively exploited Microsoft vulnerabilities addressedCSO Online
Microsoft highlighted six new and actively exploited vulnerabilities among the 60 fixes issued in today’s February Patch Tuesday releases. However, Tyler Reguly, associate director of security R&D at Fortra, says there’s good news: The issues are easy to resolve with regular Microsoft patches for Windows and Office, and none require any post patch configuration steps. […]
newswww.csoonline.comFeb 11, 2026, 1:30 AM - Microsoft Patch Tuesday security updates for February 2026 fix six actively exploited zero-daysSecurity Affairs
Microsoft Patch Tuesday security updates for February 2026 fix six actively exploited zero-day vulnerabilities. Microsoft Patch Tuesday security updates for February 2026 fix 58 new security flaws across Windows, Office, Azure, Edge, Exchange, Hyper-V, WSL, and other components, rising to 62 CVEs when third-party updates are included. Five vulnerabilities are Critical, two Moderate, and most […]
newssecurityaffairs.comFeb 10, 2026, 10:31 PM Microsoft’s Patch Tuesday updates fix roughly 60 vulnerabilities found in the company’s products.
newswww.securityweek.comFeb 10, 2026, 7:29 PM- The February 2026 Security Update ReviewZero Day Initiative
ake a closer look at some of the more interesting updates for this month, starting with the bugs under active attack: - CVE-2026-21510 - Windows Shell Security Feature Bypass Vulnerability This bug is listed as a security feature bypass, but it could also be classified as code execution. An attacker can bypass Windows SmartScreen and Windows Shell secu
vendorwww.thezdi.comFeb 10, 2026, 6:30 PM No excerpt available.
Mitigationwww.cisa.govFeb 10, 2026, 6:16 PM- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21519msrc.microsoft.com
No excerpt available.
Vendor Advisorymsrc.microsoft.comFeb 10, 2026, 6:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-34344CVSS 7.8 · High
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2026-26162CVSS 7.8 · High
Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized attacker to elevate privileges locally.
- CVE-2026-20860CVSS 7.8 · High
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2026-45635CVSS 8.1 · High
Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
- CVE-2025-54915CVSS 6.7 · Medium
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
- CVE-2025-54109CVSS 6.7 · Medium
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.