---
title: Detecting Attacks against CVE-2026-21510 and CVE-2026-21511 using Clear NDR
description: Technical guide on detecting and escalating attacks for Microsoft Outlook Spoofing (CVE-2026-21511) and Windows Shell Bypass (CVE-2026-21510) using Clear NDR.
image: https://www.stamus-networks.com/hubfs/CVE-2026-CVE-2026-21510-11-Stamus%20Blog.jpg
---

[![Stamus-Logo-with-R-color-small](https://www.stamus-networks.com/hubfs/Stamus-Logo-with-R-color-small.png "Stamus-Logo-with-R-color-small")](https://www.stamus-networks.com/?hsLang=en)

# Detecting Attacks against CVE-2026-21510 and CVE-2026-21511 using Clear NDR

 by [Stamus Networks Team](https://www.stamus-networks.com/blog/author/stamus-networks-team) | Feb 11, 2026 | [Network Detection and Response](https://www.stamus-networks.com/blog/tag/network-detection-and-response), [CVE](https://www.stamus-networks.com/blog/tag/cve), [Declarations of Compromise](https://www.stamus-networks.com/blog/tag/declarations-of-compromise), [Stamus Labs](https://www.stamus-networks.com/blog/tag/stamus-labs), [Clear NDR Enterprise](https://www.stamus-networks.com/blog/tag/clear-ndr-enterprise), [uncovered with Clear NDR](https://www.stamus-networks.com/blog/tag/uncovered-with-clear-ndr)

![](https://www.stamus-networks.com/hubfs/CVE-2026-CVE-2026-21510-11-Stamus%20Blog.jpg)

This blog describes the steps Stamus Networks customers may take to determine if any of your systems have been attacked in the past, are currently under attack or vulnerable as a result of two recent Microsoft vulnerabilities outlined in CVE-2026-21511 and CVE-2026-21510. This blog was originally published as a Stamus Networks Technical Brief, [StamusNetworks-TB-MS-CVE-022026-1](https://www.stamus-networks.com/hubfs/Library/Documents%20(PDFs)/StamusNetworks-TB-MS-CVE-022026-1.pdf?hsLang=en) (PDF).

# Background

On February 10, 2026, Microsoft published two Common Vulnerabilities and Exposure (CVE) alerts identifying vulnerabilities in Microsoft Outlook Spoofing  - [CVE-2026-21511](https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-21510) and Windows Shell Security Feature Bypass Vulnerability - [CVE-2026-21510](https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-21510). 

### Microsoft Outlook Spoofing

Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. 

### Windows Shell Security Feature Bypass Vulnerability

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

We recommend you patch any vulnerable systems as soon as possible using the most “Security Updates” released by Microsoft identified in each of the CVE announcements listed above. Users should consult the following Microsoft release announcement for patch information and potential workaround.

In the meantime, you may take the following steps to help determine if any of your systems have been attacked in the past, are currently under attack or vulnerable.

# Detection and Escalation

Please follow the steps listed below in the Clear NDR “Hunting” interface

# Create a Filter

Any CVE number can be searched in the Hunt interface.

To create a filter:

1. In Hunt, click on the magnifying icon next to any signature (first group Signatures on the Dashboard tab).

2. Click on the pencil/Edit icon on the resulting filter displayed as “Active Filters:”.

3. Type the CVE number or a text descriptor with a wildcard (*) it at each end (for example: *CVE-2026-21510* or *CVE-2026-21511* )

4. Select the checkbox “Wildcard view”

5. Click Save

You are now ready to review the results and events in the Dashboard,Host Insights and Alert views”

The example screenshot below shows how to do that for “CVE-2026-21510”

![SN-11-Feb-2026-Blog-Image-1](https://www.stamus-networks.com/hs-fs/hubfs/SN-11-Feb-2026-Blog-Image-1.png?width=842&height=449&name=SN-11-Feb-2026-Blog-Image-1.png)

## Save the Filter

The resulting filter can be saved by simply clicking on the “Save” link on the right-hand side of the “Active filter”.  Check “Shared” in the resulting dialog box if you want to make the filter available to all users. 

![SN-11-Feb-2026-Blog-Image-2](https://www.stamus-networks.com/hs-fs/hubfs/SN-11-Feb-2026-Blog-Image-2.png?width=1058&height=385&name=SN-11-Feb-2026-Blog-Image-2.png)

The newly created filter is now available in “Global Filter Sets” or “Private Filter Sets”

![SN-11-Feb-2026-Blog-Image-2b](https://www.stamus-networks.com/hs-fs/hubfs/SN-11-Feb-2026-Blog-Image-2b.png?width=1076&height=311&name=SN-11-Feb-2026-Blog-Image-2b.png)

## Review Detection Methods in Hunting

To review exactly what detection methods are available in Hunting for that specific vulnerability you can:

1. Head to the Detection Methods tab on the left-hand side in Hunt.

2. Select the “Content” option from the dropdown menu.

3. Type in the full CVE (i.e. CVE-2026-21510), hit Enter

![SN-11-Feb-2026-Blog-Image-3](https://www.stamus-networks.com/hs-fs/hubfs/SN-11-Feb-2026-Blog-Image-3.png?width=361&height=587&name=SN-11-Feb-2026-Blog-Image-3.png)![SN-11-Feb-2026-Blog-Image-4](https://www.stamus-networks.com/hs-fs/hubfs/SN-11-Feb-2026-Blog-Image-4.png?width=868&height=273&name=SN-11-Feb-2026-Blog-Image-4.png)

## Automated Escalation and RestAPI Notification

If needed, an automated escalation to a Declaration of Compromise (DoC) and API webhooks is also possible, including from historical data.

For example, if it happened 24hrs or 7 days ago it will still be detected and escalated based on that custom filter.

To do so:

1. After creating your filter as above   
2. From the right-hand side drop down menu, Policy Actions, select “Create declaration events”.

![SN-11-Feb-2026-Blog-Image-5](https://www.stamus-networks.com/hs-fs/hubfs/SN-11-Feb-2026-Blog-Image-5.png?width=938&height=316&name=SN-11-Feb-2026-Blog-Image-5.png)  
3. Choose the plus (+) next to the Threat: Name  
4. Fill in the Threat Name, Description, and Additional information.  
5. Enter an Offender Key (i.e. src_ip)  
6. Enter a Victim Key (i.e. dest_ip)  
7. Leave Victim Type “IP”  
8. Set a Kill Chain phase (i.e. Exploit)

Select “Generate DoC events from historical data”. [This will make sure historical events are also checked]  
If desired and webhooks are setup also select “Generate webhooks events from historical data”

The screenshot below shows the DoC event creation form:

![SN-11-Feb-2026-Blog-Image-6](https://www.stamus-networks.com/hs-fs/hubfs/SN-11-Feb-2026-Blog-Image-6.png?width=970&height=529&name=SN-11-Feb-2026-Blog-Image-6.png)

 

## Automated Classification and Tagging

Auto Tagging all relevant events is also an option. This will allow for any logs (alerts or protocol transaction events related to the alerts) to have a “Relevant” tag inserted in the JSON logs:

![SN-11-Feb-2026-Blog-Image-7](https://www.stamus-networks.com/hs-fs/hubfs/SN-11-Feb-2026-Blog-Image-7.png?width=365&height=119&name=SN-11-Feb-2026-Blog-Image-7.png)To do so:

1. After creating your filter as above.  
2. From the right-hand side drop down menu -  Policy Actions , Select “Tag”.  
3. Add in an optional comment and select a ruleset.  
4. Update the threat detection (upload button in the middle of the top bar on the Hunt page, on the left-hand side of History, Filter Sets )  
![SN-11-Feb-2026-Blog-Image-8](https://www.stamus-networks.com/hs-fs/hubfs/SN-11-Feb-2026-Blog-Image-8.png?width=946&height=299&name=SN-11-Feb-2026-Blog-Image-8.png)

## Export Data - SIEM / Elasticsearch / Kibana

All data generated by Clear NDR, such as alerts, protocol transactions, sightings events or Host Insights information, may be exported and shared with any SIEM or SOAR system.

Over 4000 fields are available -- from domain requests, http user agents used, hostnames, usernames logged in --  to encrypted analysis including JA3S/JA4 fingerprinting, TLS certificates and more.

Any query of the Stamus Networks data (protocol transaction or alert logs) can be exported via a regular JSON log query or visualization export.

Example of Kibana query on alert events

To export CSV data from any info of the alerts you can open the SN-ALERT dashboard in Kibana, type in the filter “alert.signature.keyword:*CVE-2026-21510*” , then you can export a CSV of any visualization using “Inspect” (see example below):

![SN-11-Feb-2026-Blog-Image-9](https://www.stamus-networks.com/hs-fs/hubfs/SN-11-Feb-2026-Blog-Image-9.png?width=671&height=370&name=SN-11-Feb-2026-Blog-Image-9.png)

Click on “Inspect” in any visualization to export a CSV

![SN-11-Feb-2026-Blog-Image-10](https://www.stamus-networks.com/hs-fs/hubfs/SN-11-Feb-2026-Blog-Image-10.png?width=671&height=323&name=SN-11-Feb-2026-Blog-Image-10.png)

## Export Data - Splunk

Any query of the Stamus Networks data (protocol transaction or alert logs a like) in Splunk can be exported via a regular Splunk query or visualization export.

Example of a Splunk query on alert events

Splunk:  

”event_type=alert "alert.signature"="*CVE-2026-21510*" 

![SN-11-Feb-2026-Blog-Image-11](https://www.stamus-networks.com/hs-fs/hubfs/SN-11-Feb-2026-Blog-Image-11.png?width=647&height=234&name=SN-11-Feb-2026-Blog-Image-11.png)

Protocol transactions

Stamus Networks provides a free Splunk app https://splunkbase.splunk.com/app/5262  that can be used to do specific searches for both CVE-2026-21510 and CVE-2026-21511.

If there are any Splunk visualizations queries that have supporting information for the CVE that needs to be exported, it can be done so by the native Splunk export functionality.

![SN-11-Feb-2026-Blog-Image-13](https://www.stamus-networks.com/hs-fs/hubfs/SN-11-Feb-2026-Blog-Image-13.png?width=671&height=471&name=SN-11-Feb-2026-Blog-Image-13.png)

# Troubleshooting and Help

Please feel free to reach out to support@stamus-networks.com with any questions or feedback.

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png) ](https://www.facebook.com/share.php?u=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fdetecting-attacks-against-cve-2026-21510-and-cve-2026-21511-using-clear-ndr%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png) ](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fdetecting-attacks-against-cve-2026-21510-and-cve-2026-21511-using-clear-ndr%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png) ](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fdetecting-attacks-against-cve-2026-21510-and-cve-2026-21511-using-clear-ndr%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fdetecting-attacks-against-cve-2026-21510-and-cve-2026-21511-using-clear-ndr%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=) [![Share on email](https://7528311.fs1.hubspotusercontent-na1.net/hub/7528311/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/email-color.png?width=24&name=email-color.png) ](mailto:?subject=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fdetecting-attacks-against-cve-2026-21510-and-cve-2026-21511-using-clear-ndr%3Futm_medium%3Dsocial%26utm_source%3Demail&body=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fdetecting-attacks-against-cve-2026-21510-and-cve-2026-21511-using-clear-ndr%3Futm_medium%3Dsocial%26utm_source%3Demail)

![Stamus Networks Team](https://www.stamus-networks.com/hubfs/Stamus%202020/Images/icon-user.png)

#### Stamus Networks Team

## Schedule a Demo of Clear NDR

[![REQUEST A DEMO](https://no-cache.hubspot.com/cta/default/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f.png)](https://cta-redirect.hubspot.com/cta/redirect/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f)

## Related posts

[![](https://www.stamus-networks.com/hubfs/U42.2%20%281%29.png) ](https://www.stamus-networks.com/blog/clear-ndr-enterprise-u42.2-is-now-available?hsLang=en)

### [Clear NDR® U42.2: A New Analyst Experience and a More Powerful AI Investigation Layer](https://www.stamus-networks.com/blog/clear-ndr-enterprise-u42.2-is-now-available?hsLang=en)

At Stamus Networks, we measure releases by how much they improve the day-to-day work of security...

[![Stamus Networks: When the Perimeter Fails, the Network Tells the Truth](https://www.stamus-networks.com/hubfs/SN-Perimeter-Fails-Blog-Featured.jpg) ](https://www.stamus-networks.com/blog/when-the-perimeter-fails-the-network-tells-the-truth?hsLang=en)

### [When the Perimeter Fails, the Network Tells the Truth](https://www.stamus-networks.com/blog/when-the-perimeter-fails-the-network-tells-the-truth?hsLang=en)

SentinelOne's "Edge Decay" research names the threat. Here's how network detection and response...

[![When EDR Goes Dark: Why Network Visibility is Your Last Line of Truth](https://www.stamus-networks.com/hubfs/SN-EDR-Goes-Dark-Blog-Featured.jpg) ](https://www.stamus-networks.com/blog/when-edr-goes-dark-why-network-visibility-is-your-last-line-of-truth?hsLang=en)

### [When EDR Goes Dark: Why Network Visibility is Your Last Line of Truth](https://www.stamus-networks.com/blog/when-edr-goes-dark-why-network-visibility-is-your-last-line-of-truth?hsLang=en)

I've spent a significant part of my career participating in [NATO cyber defense exercises](https://www.stamus-networks.com/nato-ccdcoe-participation?hsLang=en) -...

[![Stamus-Logo-with-R-white](https://www.stamus-networks.com/hs-fs/hubfs/Stamus-Logo-with-R-white.png?width=2000&height=536&name=Stamus-Logo-with-R-white.png "Stamus-Logo-with-R-white")](https://www.stamus-networks.com/?hsLang=en)

 ABOUT STAMUS® NETWORKS

Stamus Networks is the network intelligence foundation for AI-powered security operations and the creator of the Clear NDR® system. Built on Suricata, the world's leading open-source network security engine, Clear NDR transforms raw network traffic into actionable security insights with unmatched transparency, customization, and effectiveness. Designed to close visibility gaps and reduce alert fatigue, Clear NDR is trusted by leading financial institutions, government agencies, and has been battle-tested over ten years in NATO's largest cybersecurity exercises. Stamus Networks empowers security teams with greater control, fewer false positives, faster response times, and a more responsive, open approach than legacy vendors.

- [**](https://www.linkedin.com/company/stamus-networks)
- [**](https://twitter.com/StamusN/)
- [**](https://www.youtube.com/Stamus-Networks)
- [* *](https://discord.gg/JUMSU9uA)
- <https://www.facebook.com/StamusNetworks>

Paris, FranceIndianapolis, USA

**[contact@stamus-networks.com](mailto:contact@stamus-networks.com)

[Privacy](https://www.stamus-networks.com/privacy-policy?hsLang=en)

 © 2014-2026 Stamus Networks, Inc. All rights Reserved.