CISA's list that day

5 February 2026

On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in React Native Community CLI and SmarterTools SmarterMail. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-24423Missing Authentication for Critical FunctionSmarterTools SmarterMailPatch nowRansomware use, listed within a year0.88
CVE-2025-11953OS Command InjectionReact Native Community CLIPatch this weekEPSS 0.940.94

Other changes that day

  1. CVE-2026-24423 SmarterTools SmarterMailRansomware use: Unknown to Known.