CISA's list that day
10 February 2026
On CISA added 6 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Windows and Microsoft Office. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-21510Shell Protection Mechanism Failure | Microsoft Windows | Patch soon | 0.24 | ||
| CVE-2026-21513MSHTML Framework Protection Mechanism Failure | Microsoft Windows | Patch soon | 0.16 | ||
| CVE-2026-21525NULL Pointer Dereference | Microsoft Windows | Patch soon | 0.05 | ||
| CVE-2026-21533Improper Privilege Management | Microsoft Windows | Patch soon | 0.04 | ||
| CVE-2026-21519Type Confusion | Microsoft Windows | Patch soon | 0.02 | ||
| CVE-2026-21514Word Reliance on Untrusted Inputs in a Security Decision | Microsoft Office | Patch soon | 0.02 |