CISA's list that day

10 February 2026

On CISA added 6 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Windows and Microsoft Office. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-21510Shell Protection Mechanism FailureMicrosoft WindowsPatch soon0.24
CVE-2026-21513MSHTML Framework Protection Mechanism FailureMicrosoft WindowsPatch soon0.16
CVE-2026-21525NULL Pointer DereferenceMicrosoft WindowsPatch soon0.05
CVE-2026-21533Improper Privilege ManagementMicrosoft WindowsPatch soon0.04
CVE-2026-21519Type ConfusionMicrosoft WindowsPatch soon0.02
CVE-2026-21514Word Reliance on Untrusted Inputs in a Security DecisionMicrosoft OfficePatch soon0.02

Other changes that day

  1. CVE-2026-21513 Microsoft WindowsEdited: description and name.