Microsoft has released urgent security updates to address multiple zero-day vulnerabilities in Windows and Office, which are already being actively exploited by attackers. These vulnerabilities allow "one-click" attacks, where users can activate malware with a simple click on a malicious link or by opening a specially crafted Office file. Zero-day vulnerabilities are security issues that are exploited before the vendor releases a patch. One of the most critical vulnerabilities, CVE-2026-21510, affects the Windows shell and allows attackers to bypass SmartScreen protection, executing malicious code on the compromised system. Another vulnerability, CVE-2026-21513, has been found in MSHTML, Microsoft's old browser engine, which continues to pose risks in enterprise environments. These issues highlight the need for rapid patch management and a deep defense strategy.
Sources
Latest News
16:23
15:51
15:21
14:55
14:38
See more news