Cyber Resilience
← All news
Confirmed

Microsoft Apps: CVSS (Max): 8.6

Our takeMicrosoft's February security updates are out, with multiple critical RCEs (CVSS 9.8-10.0) across Office, Edge, Azure, Dynamics, and ESU. Patch now: a hypervisor or identity compromise reaches everything downstream.
Sources (17)
What this means for you — Security leader:Apply February 2026 Microsoft patches for Office, Edge, Azure, Dynamics, ESU and the rest. Prioritize the CVSS 9.8–10.0 items (Office RCE, Edge, ESU, Azure) as they reach remote code execution or full compromise.
What this means for you — Lean IT orgs:Install the February 2026 Microsoft updates for Office, Edge, Windows and Azure as soon as you can. Most of these fixes have no workaround — patching is the only protection.
What this means for you — MSP:Patch all managed clients for the February 2026 Microsoft bundle this cycle. Highest risk items are Office (CVSS 10), Edge (9.8), ESU (9.8) and Azure (10.0) — schedule and verify deployment across every stack you support.
What this means for you — Researcher:Review the full ASB-2026.021x advisories for technical detail on the Office, Edge, Azure and Dynamics flaws.