CISA's list that day
5 February 2026
On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in React Native Community CLI and SmarterTools SmarterMail. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-24423Missing Authentication for Critical Function | SmarterTools SmarterMail | Patch nowRansomware use, listed within a year | 0.88 | ||
| CVE-2025-11953OS Command Injection | React Native Community CLI | Patch this weekEPSS 0.94 | 0.94 |