Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Microsoft fixes exploited zero-day bugs in Windows, Office

Microsoft has released security updates for Windows and Office to address vulnerabilities that are being actively exploited by hackers, according to the company.

The flaws include two zero-day bugs that can be exploited through simple actions, such as clicking malicious links or opening infected Office files.

One of these, CVE-2026-21510, affects all supported Windows versions and allows attackers to bypass security features like SmartScreen, potentially enabling malware installation.

The second, CVE-2026-21513, resides in Microsoft’s legacy MSHTML browser engine and can be used to plant malware by bypassing security measures.

Microsoft acknowledged the involvement of Google’s Threat Intelligence Group in discovering these vulnerabilities.

Security researcher Dustin Childs noted that while user interaction is required, the bugs could be used to remotely execute malicious code.

Additionally, reports indicate that three other zero-day vulnerabilities have been patched in recent updates.

🔗 Source: TechCrunch

🧠 Food for thought

Implications, context, and why it matters.

This month brought heavier security pressure than the headline numbers

  • Microsoft patched six actively exploited zero-day vulnerabilities this month, not two 1.
  • Four additional in-the-wild flaws let attackers raise system permissions, meaning they can take deeper control of a PC, or trigger a denial-of-service (DoS), an attack that disrupts a system so it can’t be used. The affected areas included Windows Remote Desktop Services and the Desktop Window Manager 1.
  • Attackers kept returning to the Desktop Window Manager, with an exploited zero-day fixed for the second month in a row 1.

Attackers are shifting attention to AI-powered developer tools

  • This month’s patches also fixed remote code execution issues tied to GitHub Copilot and several integrated development environments (IDEs), including VS Code, Visual Studio, and JetBrains products 1.
  • Developers draw attention because their machines often store sensitive data such as API keys and secrets that can open critical infrastructure, including privileged Amazon Web Services (AWS) or Microsoft Azure API keys 1.
  • Prompt injection, which tricks an AI agent into running malicious code or commands, can help compromise developer environments 1.

Recent Microsoft developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.