Monthly Fallout Report
February 2026 Fallout
58 vulnerabilities but 6 actively exploited zero-days — the highest exploited count in a single Patch Tuesday in years. KB5077181 finally fixed January's boot nightmare, then promptly introduced its own boot loops on Dell and 24H2 systems.
Tired of patch chaos? Automox automates patching across Windows, Mac, and Linux — so you're never caught off guard on Patch Tuesday.
Try Free →Fallout Timeline
February 2026 is relatively light by the numbers — 58 vulnerabilities, 5 Critical — but what it lacks in volume it makes up for in urgency: six actively exploited zero-days, the most in a single Patch Tuesday in years. Three of those six are security feature bypass flaws that chain together perfectly for attackers. CVE-2026-21510 (Windows Shell/SmartScreen, CVSS 8.8) lets a single click on a malicious shortcut suppress all security dialogs and run attacker-controlled content without any warning. CVE-2026-21513 (MSHTML/Internet Explorer, CVSS 8.8) allows an attacker to bypass browser security controls by tricking a victim into opening a crafted HTML or .lnk file. CVE-2026-21514 (Microsoft Word OLE, CVSS 7.8) bypasses OLE mitigations in Office 2016–2024 and M365 Apps via a malicious .docx — Preview Pane is not an attack vector here. All three were attributed to Google Threat Intelligence Group alongside Microsoft's own teams, strongly suggesting a coordinated nation-state or commercial spyware campaign. The remaining three zero-days round out a brutal month: CVE-2026-21519 is a DWM Elevation of Privilege (CVSS 7.8) — the second exploited-in-wild DWM zero-day in two months, this one using type confusion to reach SYSTEM. CVE-2026-21533 is a Windows Remote Desktop Services EoP confirmed by CrowdStrike — the exploit binary modifies a service config key to add a new user to the Administrator group. CrowdStrike warned threat actors will "accelerate or monetize" now it's public. CVE-2026-21525 is a RasMan DoS discovered by Acros Security/0patch in a public malware repository — a standard user with no elevated privileges can crash your VPN service with a small script, cutting off endpoints on fail-close policies. Also notable: CVE-2026-21511 (Outlook Spoofing, CVSS 7.5, Preview Pane is an attack vector) is rated "Exploitation More Likely." February's KB5077181 also bundles the full resolution of January's UNMOUNTABLE_BOOT_VOLUME boot failures — but not without adding some new problems of its own.
Windows Shell / SmartScreen Security Feature Bypass — one click on a malicious shortcut or link suppresses all security dialogs. All supported Windows versions affected. Attributed to Google Threat Intelligence Group + Microsoft — likely nation-state campaign.
MSHTML / Internet Explorer Security Feature Bypass — open a crafted HTML or .lnk file to bypass browser security controls entirely. Also attributed to Google TIG — same likely campaign as CVE-2026-21510.
Microsoft Word OLE Security Feature Bypass — crafted .docx bypasses COM/OLE mitigations in Office 2016–2024 and M365 Apps. Preview Pane is NOT an attack vector. Third in the trio attributed to Google TIG.
Windows Remote Desktop Services EoP — exploit binary modifies a service config key to add new user to the Administrator group. Confirmed by CrowdStrike, who warned threat actors will "accelerate or monetize" now it's public.
Desktop Window Manager EoP — type confusion flaw lets a local low-privilege attacker reach SYSTEM with no user interaction. The second exploited-in-wild DWM zero-day in consecutive months.
Windows RasMan (VPN service) Denial of Service — standard user with no elevated privileges can crash the VPN service with a small script. Found by Acros Security/0patch in a public malware repository. Fail-close VPN environments lose network access instantly.
Sources: BleepingComputer · Tenable · Krebs on Security · SecurityWeek
KB5077181 was supposed to be the update that finally cleaned up January's boot mess — and it did resolve the UNMOUNTABLE_BOOT_VOLUME failures. But it also introduced its own chaos within 48 hours of release. Reports flooded in of Windows 11 24H2 and 25H2 devices entering infinite boot loops — some cycling more than 15 times before landing on a broken login screen with a System Event Notification Service (SENS) error: "The specified procedure could not be found." The Secure Boot certificate changes bundled into KB5077181 (replacing expiring 2011-era certs) appear to conflict with certain OEM firmware — Dell and Alienware machines are the most-reported casualties, hitting KERNEL_SECURITY_CHECK_FAILURE on boot. Additional reported symptoms include complete DHCP failure causing loss of internet connectivity, and install errors 0x800f0983 and 0x800f0991 on some hardware. Making things worse: Microsoft listed zero known issues on the KB article or Windows Release Health dashboard as of February 15, leaving admins to discover the problems entirely through Reddit, Microsoft Q&A, and community forums. Workaround: uninstall KB5077181 via Control Panel or from WinRE using wusa /uninstall /kb:5077181 /quiet /norestart, then pause Windows Update to prevent automatic reinstall.
- Windows 11 24H2 / 25H2 KB5077181 infinite boot loops — 15+ restart cycles, SENS "specified procedure could not be found" at login. Uninstall via Control Panel or WinRE. Pause updates afterward.
- Dell / Alienware Secure Boot cert changes conflict with OEM firmware — KERNEL_SECURITY_CHECK_FAILURE boot errors. Uninstall KB5077181 and pause updates.
- Windows 11 24H2 / 25H2 (affected systems) DHCP failure causing complete loss of internet connectivity alongside boot loop symptoms.
- All Windows 11 Microsoft health dashboard listed zero known issues as of Feb 15 — no KIR deployed, community-only discovery.
Sources: Neowin · Microsoft Q&A · r/sysadmin
By the end of February, most of the KB5077181 chaos had settled. For systems that could still boot, uninstalling the update and pausing Windows Update provided relief. For machines already locked in boot loops from the December–January cascade, Microsoft advised contacting Support for Business — automatic recovery was not available for the hardest-hit systems. The January UNMOUNTABLE_BOOT_VOLUME failure was confirmed fully resolved by KB5077181 for any devices not already bricked before the fix shipped. Nvidia black screen crashes and gaming regressions (frame rate drops, artifacts in Forza Horizon 5) from January were confirmed fixed. Explorer.exe crashes that made Windows nearly unusable on login are gone. The six exploited zero-days are patched — despite the operational headaches, February is a month you cannot skip. The three SmartScreen/MSHTML/Word bypass zero-days used in combination form a complete phishing-to-execution chain; leaving them unpatched in an enterprise environment is genuinely dangerous. No second OOB update was needed — unlike January, Microsoft contained the fallout without emergency patches.
- Windows 11 24H2 / 25H2 KB5077181 boot loops — uninstall resolves for most. Systems already unbootable from the Dec/Jan cascade need manual WinRE recovery or Microsoft Support for Business.
- Windows 11 (all) January UNMOUNTABLE_BOOT_VOLUME issue — fully resolved by KB5077181 for systems not already affected before the fix shipped.
- Windows 11 (gaming) Nvidia black screen and Forza Horizon artifacts from January — confirmed fixed in KB5077181.
- Windows 11 (all) Explorer.exe crashes on login — resolved in KB5077181.
Sources: BleepingComputer: KB5077181 boot fix · Windows Latest · Windows Forum
Resources