Russia is hacking zero-days again

Russia is hacking zero-days again

Source: YouTube · John Hammond · published Feb 19, 2026 · 16:51

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Microsoft released an emergency out-of-band update to patch an actively exploited zero-day vulnerability in Microsoft Office tracked as CVE-2026-21509 0:09-0:19.

Key Takeaways:
• Microsoft typically issues fixes during "Patch Tuesday," but this emergency release indicates a high-risk, active threat 0:00-0:07.
• The vulnerability is a security feature bypass with a CVSS severity score of 7.8 0:31-0:42.
• The flaw involves reliance on untrusted inputs and is being tracked by security reports 0:22-0:26.

Users should apply this update immediately to secure their systems against active exploitation.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

On the second Tuesday of every month, Microsoft does what they call patch Tuesday, where they release different updates or security fixes to address bugs or vulnerabilities. But sometimes they release emergency outofband updates to patch and fix actively exploited zeroday vulnerabilities. And that is exactly the case with this recent bug in Microsoft Office. This is a news report from Bleeping Computer where they're tracking a security feature bypass vulnerability tracked as CVE 202621509. And if you take a look on the Microsoft resource center, it's literally called a security feature bypass vulnerability with a max severity of important. It is a high severity risk with a big old CVSs of 7.8. Still something to take seriously here. But the description isn't all that helpful. They say, "Oh…