Skip to content
Noroxi

Patch Tuesday

February 2026

On the second Tuesday of each month Microsoft, Adobe, SAP, Siemens and Schneider Electric publish in bulk; Oracle on the third Tuesday of January, April, July and October. Records published that day, from our own database, sorted by action score: KEV and mature exploits first.

How it is computed: CNA stamp + publication date (two-day window, UTC). No claim of a one-to-one match with the vendor bulletin; out-of-band updates land on other days.

137 records · 6 KEV

Affecting your stack

This month's records that match the products and versions in your stack.

Sign in to see the ones matching your stack; records and notifications are free. →

Microsoft · February 10

54 · 6 KEV · 1 critical
  • CVE-2026-21510
    72This week

    Windows Shell Security Feature Bypass Vulnerability

    HighCVSS 8.8KEVWeaponizedEPSS 25%

    microsoft · windows 10 1607Feb 10, 2026

  • CVE-2026-21513
    70This week

    MSHTML Framework Security Feature Bypass Vulnerability

    HighCVSS 8.8KEVWeaponizedEPSS 16%

    microsoft · windows 10 1607Feb 10, 2026

  • CVE-2026-21519
    62This week

    Desktop Window Manager Elevation of Privilege Vulnerability

    HighCVSS 7.8KEVWeaponizedEPSS 2%

    microsoft · windows 10 1607Feb 10, 2026

  • CVE-2026-21533
    62This week

    Windows Remote Desktop Services Elevation of Privilege Vulnerability

    HighCVSS 7.8KEVWeaponizedEPSS 4%

    microsoft · windows 10 1607Feb 10, 2026

  • CVE-2026-21514
    61This week

    Microsoft Word Security Feature Bypass Vulnerability

    HighCVSS 7.8KEVWeaponizedEPSS 2%

    microsoft · 365 appsFeb 10, 2026

  • Windows Remote Access Connection Manager Denial of Service Vulnerability

    MediumCVSS 6.2KEVWeaponizedEPSS 5%

    microsoft · windows 10 1607Feb 10, 2026

  • Azure SDK for Python Remote Code Execution Vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    microsoft · azure conversation authoring client libraryFeb 10, 2026

  • Power BI Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    microsoft · power bi report serverFeb 10, 2026

  • Windows Hyper-V Security Feature Bypass Vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    microsoft · windows 10 1607Feb 10, 2026

  • GitHub Copilot and Visual Studio Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    microsoft · visual studio 2022Feb 10, 2026

  • GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    microsoft · visual studio codeFeb 10, 2026

  • Microsoft Defender for Endpoint Linux Extension Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    microsoft · defender for endpointFeb 10, 2026

+42 moreAll records of the vendor

Adobe · February 10

44 · 0 KEV · 0 critical

+32 moreAll records of the vendor

SAP · February 10

26 · 0 KEV · 2 critical
  • CVE-2026-0488
    39Monitor

    Code Injection vulnerability in SAP CRM and SAP S/4HANA (Scripting Editor)

    CriticalCVSS 9.9No exploitEPSS 1%

    sap · netweaver application server abapFeb 10, 2026

  • CVE-2026-0509
    38Monitor

    Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform

    CriticalCVSS 9.6No exploitEPSS 0%

    sap · netweaver as abap kernelFeb 10, 2026

  • XML Signature Wrapping in SAP NetWeaver AS ABAP and ABAP Platform

    HighCVSS 8.8No exploitEPSS 1%

    sap · sap basisFeb 10, 2026

  • CVE-2026-0508
    32Monitor

    Open Redirect vulnerability in SAP BusinessObjects Business Intelligence Platform

    HighCVSS 8.1No exploitEPSS 0%

    sap · businessobjects business intelligence platformFeb 10, 2026

  • CVE-2026-0485
    30Monitor

    Denial of service (DOS) vulnerability in SAP BusinessObjects BI Platform

    HighCVSS 7.5No exploitEPSS 0%

    sap · businessobjects business intelligence platformFeb 10, 2026

  • CVE-2026-0490
    30Monitor

    Denial of service (DOS) in SAP BusinessObjects BI Platform

    HighCVSS 7.5No exploitEPSS 0%

    sap · businessobjects business intelligence platformFeb 10, 2026

  • Denial of service (DOS) in SAP Supply Chain Management

    HighCVSS 7.7No exploitEPSS 0%

    sap · advanced planning and optimizationFeb 10, 2026

  • Missing Authorization check in SAP Solution Tools Plug-In (ST-PI)

    HighCVSS 7.7No exploitEPSS 0%

    sap · solution tools plug-inFeb 10, 2026

  • CVE-2026-0484
    26Monitor

    Missing Authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA

    MediumCVSS 6.5No exploitEPSS 0%

    sap · sap basisFeb 10, 2026

  • Denial of service (DOS) vulnerability in SAP BusinessObjects Business Intelligence Platform (AdminTools)

    MediumCVSS 6.5No exploitEPSS 0%

    sap · businessobjects business intelligence platformFeb 10, 2026

  • CVE-2026-0505
    24Monitor

    Multiple vulnerabilities in BSP Applications of SAP Document Management System

    MediumCVSS 6.1No exploitEPSS 0%

    sap · document management systemFeb 10, 2026

  • Multiple vulnerabilities in BSP Applications of SAP Document Management System

    MediumCVSS 6.1No exploitEPSS 0%

    sap · document management systemFeb 10, 2026

+14 moreAll records of the vendor

Siemens · February 10

11 · 0 KEV · 0 critical
  • A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP2).

    HighCVSS 8.5No exploitEPSS 0%

    siemens · sinec nmsFeb 10, 2026

  • A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3), User Management Component (UMC) (All versions < V2.15.2.1).

    HighCVSS 8.5No exploitEPSS 0%

    siemens · sinec nmsFeb 10, 2026

  • A vulnerability has been identified in NX (All versions < V2512), NX (Managed Mode) (All versions < V2512).

    HighCVSS 7.3No exploitEPSS 0%

    siemens · nxFeb 10, 2026

  • A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512).

    HighCVSS 7.3No exploitEPSS 0%

    siemens · simcenter femapFeb 10, 2026

  • A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512).

    HighCVSS 7.3No exploitEPSS 0%

    siemens · simcenter femapFeb 10, 2026

  • A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512).

    HighCVSS 7.3No exploitEPSS 0%

    siemens · simcenter femapFeb 10, 2026

  • A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512).

    HighCVSS 7.3No exploitEPSS 0%

    siemens · simcenter femapFeb 10, 2026

  • A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512).

    HighCVSS 7.3No exploitEPSS 0%

    siemens · simcenter femapFeb 10, 2026

  • A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512).

    HighCVSS 7.3No exploitEPSS 0%

    siemens · simcenter femapFeb 10, 2026

  • A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07).

    MediumCVSS 6.3No exploitEPSS 0%

    siemens · syngo.plaza vb30eFeb 10, 2026

  • A vulnerability has been identified in Polarion V2404 (All versions < V2404.5), Polarion V2410 (All versions < V2410.2).

    MediumCVSS 6.2No exploitEPSS 0%

    siemens · polarion v2404Feb 10, 2026

All records of the vendor

Schneider Electric · February 10

2 · 0 KEV · 0 critical
  • CVE-2026-1226
    28Monitor

    CWE‑94: Improper Control of Generation of Code vulnerability exists that could cause execution of untrusted or unintended code within the ap

    HighCVSS 7.0No exploitEPSS 0%

    schneider electric · ecostruxure building operation workstationFeb 11, 2026

  • CVE-2026-1227
    28Monitor

    CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized disclosure of local files,

    HighCVSS 7.0No exploitEPSS 0%

    schneider electric · ecostruxure building operation workstationFeb 11, 2026

All records of the vendor