Fri, 13 Feb 2026

Microsoft Issues Urgent Warning Over Critical Vulnerabilities

Khaborwala Online Desk

Published: 13 Feb 2026, 04:55 pm

Photo: Collected

Microsoft has identified multiple critical security flaws in its Windows and Office software, which are already being actively exploited by hackers. The company has released urgent updates to address several zero-day vulnerabilities—security gaps that attackers exploit before a fix is widely available.

These attacks typically follow a “one-click” pattern, where a user inadvertently clicks a malicious link, allowing malware to infiltrate their system. In some instances, opening a malicious Office file alone can trigger the exploit. According to Microsoft, at least two vulnerabilities rely on users being tricked into clicking fraudulent links, while another is activated by opening compromised Office documents.

The company has cautioned that detailed information on exploiting these flaws has already surfaced publicly, potentially increasing the risk of attacks. Microsoft has not disclosed exactly where this information was released.

One prominent vulnerability, CVE-2026-21510, affects the Windows shell. This flaw enables hackers to bypass Microsoft’s SmartScreen protection, which typically blocks dangerous links and files. Security expert Dustin Childs explained that, although a user must click a link or shortcut file to trigger the exploit, successful remote code execution in this manner remains rare. Google’s Threat Intelligence team assisted in identifying this vulnerability and confirmed that it is being widely abused. Exploitation can allow malware to run silently, increasing the risk of ransomware or data theft.

Another vulnerability, CVE-2026-21513, exists in MSHTML, the legacy browser engine still used by certain applications despite Internet Explorer’s retirement. This flaw allows attackers to bypass security controls and install malware on affected systems.

Security analyst Brian Krebs reported that Microsoft has patched three additional zero-day vulnerabilities that were also actively exploited. Experts strongly urge users to install updates immediately, as any delay leaves systems increasingly vulnerable.

Summary of Critical Vulnerabilities

CVE IDAffected ComponentExploit MethodRisk
CVE-2026-21510Windows ShellMalicious link/shortcut clickBypasses SmartScreen; remote code execution possible
CVE-2026-21513MSHTML (legacy browser)Malicious web content/fileMalware installation via legacy apps
Others (3)Windows/OfficeVariousActively exploited; details unspecified

Users of Windows and Office are strongly advised to apply all pending updates immediately to mitigate the threat posed by these critical zero-day vulnerabilities.

Questions Over Dhaka-11 Vote Count

Qayyum Questions Dhaka-11 Vote ResultM A Qayyum has questioned the vote count in the Dhaka-11 consti...

BNP Candidate Demands Fresh Election in Dhaka-14

The defeated Bangladesh Nationalist Party (BNP) candidate for the Dhaka-14 constituency, Sanjida Isl...

NSW Unveils Landmark Reforms for All-Ages Music

New South Wales is poised to rejuvenate its live music scene with a suite of reforms aimed at making...

BNP Leader Reopens Awami League Office Post-Election

In a surprising political gesture following a recent election victory, Abu Daud Pradhan, president o...

“No” Vote Triumphs in Six Greater Chittagong Constituencies

While the nationwide referendum held alongside the 13th national parliamentary elections yesterday o...

A Century of Women’s Liberation in Bangladesh

For over a century, the struggle for women’s emancipation in this land has been more than a chronicl...

Britney Spears Sells Entire Music Catalog for $200 Million

Pop icon Britney Spears has taken a decisive step in retreating from the entertainment world by sell...

Photo: Collected

Mitali Das Releases Romantic New Single

Renowned contemporary singer Mitali Das has lent her voice to a fresh musical release titled “Chokhe...

"After the election victory, Bangladesh Bank removed all obstacles in mobile banking."

Dhaka, 13 February 2026 – Bangladesh Bank has officially lifted the temporary restrictions on mobile...

Seven Women Secure Seats in Bangladesh Elections

As the results of the 13th National Parliament elections continue to emerge, early reports indicate...

Jamaat-e-Islami Headquarters Left Deserted Post-Election

Just a day after the 13th national parliamentary elections, the central office of Bangladesh Jamaat-...

Five Candidates Boycott Votes Amid Alleged Irregularities

The thirteenth National Parliament elections and associated referenda were conducted peacefully acro...