Microsoft has issued security updates to address several vulnerabilities in Windows and Office that, according to the company, are already being actively exploited by hackers to infiltrate users’ systems.
These attacks require minimal effort from victims. In some cases, a single click is enough for an attacker to install malware or gain unauthorized access. At least two of the flaws can be triggered if a user clicks a malicious link on a Windows device, while another vulnerability can compromise a system simply by opening a specially crafted Office file.
The issues are classified as zero-day vulnerabilities, meaning attackers were taking advantage of the flaws before Microsoft had the opportunity to release patches.
Microsoft noted that technical details explaining how to exploit the bugs have now been made public, potentially raising the risk of further attacks. In its advisories, the company credited researchers from Google’s Threat Intelligence Group for helping uncover the vulnerabilities.
One of the most serious flaws, identified as CVE-2026-21510, affects the Windows shell—the component responsible for the operating system’s user interface. Microsoft said the vulnerability impacts all supported versions of Windows. If a user clicks a malicious link, the flaw can allow attackers to bypass Microsoft’s SmartScreen protection, which is designed to block harmful files and websites.
Security researcher Dustin Childs explained that the bug could be used to remotely install malware on a victim’s machine.
“There is user interaction here, as the client needs to click a link or a shortcut file,” Childs wrote in a blog post. “Still, a one-click bug to gain code execution is a rarity.”
A spokesperson for Google confirmed that the Windows shell vulnerability is under “widespread, active exploitation.” Successful attacks, the spokesperson said, enable silent malware execution with elevated privileges, creating a significant risk of deeper system compromise, ransomware deployment, or data theft.
Another vulnerability, tracked as CVE-2026-21513, was discovered in MSHTML, Microsoft’s proprietary browser engine that powered Internet Explorer. Although Internet Explorer has long been discontinued, MSHTML remains embedded in modern versions of Windows to support legacy applications. Microsoft said this flaw can also be used to bypass built-in security protections and deliver malware.
In addition, independent security journalist Brian Krebs reported that Microsoft patched three more zero-day vulnerabilities that were also being actively exploited.



