CVE-2026-21510
Windows Shell Security Feature Bypass Vulnerability
- Published
- Feb 10, 2026
- Updated
- Aug 19, 2026
- Assigning CNA
- microsoft
- Evidence observed
- Feb 10, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HModerate · next 30 days
- Percentile
- 98.0%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
Sources
4Builders and research notes for exploiting CVE-2026-21514 (Protected View bypass) and CVE-2026-21510 (RCE) in MS Office, including obfuscation and alternative payload vectors.
- EpSiLoNPoInTlnkExploit
Generates obfuscated .lnk files exploiting CVE-2026-21510 with LNK stomping, encrypted payloads, and anti-forensics for authorized penetration testing and red team operations.
- CVE-2026-32202Research
Technical analysis of CVE-2026-32202, a zero-click NTLM credential coercion via crafted .lnk Control Panel applet items in Windows Explorer.
Generates LNK files with crafted _IDCONTROLW structures to research Windows Shell spoofing vulnerabilities CVE-2026-21510 and CVE-2026-32202, including reverse engineering of shell32.dll internals.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.