CVE-2026-21533
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: Feb. 18, 2026
7 articles
EPSS Score
Source: FIRST.org · 2026-05-24
17.35%
probability
This CVE has a 17.35% probability
of being exploited in the next 30 days.
0%
Top 95.1th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroWindows Remote Desktop Services Elevation of Privilege Vulnerability
Google Project Zero
Patched
Feb. 10, 2026
Reported by
Advanced Research Team, CrowdStrike
Exploits & PoC
fevar54/CVE-2026-21533_Scanner.py
Este repositorio contiene una herramienta de **detección** para la vulnerabilidad CVE-2026-21533, una falla de gestión de privilegios en los Servicios
0
1 repo — triés par ⭐
Rechercher sur GitHub ↗
CISA Adds Six Known Exploited Vulnerabilities to Catalog
CISA-Advisories
Feb 10, 2026
Microsoft Patches 59 Vulnerabilities Including Six Actively Exploited Zero-Days
TheHackerNews
Feb 11, 2026
Microsoft February 2026 Patch Tuesday fixes 6 zero-days, 58 flaws
BleepingComputer
Feb 10, 2026
Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws
BleepingComputer
Mar 10, 2026
Microsoft’s February 2026 Patch Tuesday Addresses 54 CVEs (CVE-2026-21510, CVE-2026-21513)
Tenable-Research
Feb 10, 2026
Microsoft Patch Tuesday matches last year’s zero-day high with six actively exploited vulnerabilities
CyberScoop
Feb 10, 2026
CVE-2026-21533 Windows Remote Desktop Services Elevation of Privilege Vulnerability
Microsoft-MSRC
Feb 10, 2026
Signal Intelligence
Confidence
92%
EPSS
17.35%
Mentions
7
Last Seen
Mar 10, 2026
CNA Information
Analyst Note
CVE-2026-21533 is confirmed as an actively exploited zero-day with strong corroboration from multiple reputable sources (TheHackerNews, BleepingComputer, Tenable, CISA) reporting Microsoft's February 2026 patch addressing six zero-days in the wild. The vulnerability is also tracked by Google Project Zero, and the HIGH severity CVSS score (7.8) combined with privilege escalation capability in a widely-deployed OS component provides additional validation.
Threat Actors 2
Ice Fog
apt_group
Information theft and espionage
🇨🇳 CN
Nomad Panda
apt_group
Information theft and espionage
🇨🇳 CN
Triage Info
Decided atFeb 18, 2026