U.S. CISA adds Microsoft Office and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog

3 Min Read

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Office and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Microsoft Office and Microsoft Windows flaws to its Known Exploited Vulnerabilities (KEV) catalog.

- Advertisement -

Below are the flaws added to the catalog:

  • CVE-2026-21510 Microsoft Windows Shell Protection Mechanism Failure Vulnerability
  • CVE-2026-21513 Microsoft MSHTML Framework Security Feature Bypass Vulnerability
  • CVE-2026-21514 Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability
  • CVE-2026-21519 Microsoft Windows Type Confusion Vulnerability
  • CVE-2026-21525 Microsoft Windows NULL Pointer Dereference Vulnerability
  • CVE-2026-21533 Windows Remote Desktop Services Elevation of Privilege Vulnerability 

This week, Microsoft Patch Tuesday security updates for February 2026 fixed 58 new security flaws across Windows, Office, Azure, Edge, Exchange, Hyper-V, WSL, and other components, rising to 62 CVEs when third-party updates are included. Six flaws addressed this month are actively exploited in the wild, three of them publicly known.


What do you think? Post a comment.


Below is the description of the vulnerabilities addressed by the IT giant and that CISA added to the catalog:

- Advertisement -

EXPLORE MORE

ShinyHunters leaked 600K+ Canada Goose customer records, but the firm denies it was breached

ShinyHunters leaked 600,000+ Canada Goose customer records, though the company insists its…

Resurfaced Childhood Photo of Hasan Piker Triggers Online Debate Over Wealth and Authenticity

An old photograph of political commentator and Twitch streamer Hasan Piker riding…

The Songwriter Who Taught America How to Love: Remembering Dolly Parton

There are rare figures in American culture who do not merely occupy…

Earth’s Core Could Be Hiding the Equivalent of up to 45 Oceans of Water

The Earth’s core might not be what we once thought. Credit: Argonne…

Malicious npm and PyPI packages linked to Lazarus APT fake recruiter campaign

Researchers found malicious npm and PyPI packages tied to a fake recruitment…

Canadian journalists warned not to call 9/11 a ‘terrorist attack’

(Journalists and editors employed by the Canadian Broadcasting Corporation (CBC) were warned…

  • CVE-2026-21510 (CVSS score of 7.5 – High)
    A Windows SmartScreen and Shell prompt bypass that allows attackers to evade security warnings by tricking users into opening a crafted malicious link or shortcut file.
  • CVE-2026-21513 (CVSS score of 8.8 – High)
    An Internet Explorer security control bypass that can lead to code execution when a victim opens a malicious HTML page or LNK file.
  • CVE-2026-21514 (CVSS score of 8.1 – High)
    A Microsoft 365 and Office flaw that bypasses OLE security mitigations, enabling malicious activity when a specially crafted Office document is opened.
  • CVE-2026-21519 (CVSS score of 7.8 – High)
    A Windows Desktop Window Manager vulnerability that enables local privilege escalation and elevated system access.
  • CVE-2026-21525 (CVSS score of 6.5 – Medium)
    A Windows Remote Access Connection Manager bug that can be abused by a local attacker to cause a denial-of-service condition.
  • CVE-2026-21533 (CVSS score of 8.8 – High)
    A Windows Remote Desktop Services vulnerability that allows attackers to escalate privileges to SYSTEM.

Microsoft labeled CVE-2026-21510, CVE-2026-21514 and CVE-2026-21513 as “publicly disclosed”.

The company credited Google Threat Intelligence Group, its internal security teams, and an anonymous researcher for discovering CVE-2026-21510 and CVE-2026-21514, while Microsoft and GTIG reported the vulnerability CVE-2026-21513.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by March 3rd, 2026.

Pierluigi Paganini



Share This Article

CIA Director Pushed Trump-Putin-Zelensky Summit During Moscow Visit: Report

Yet another take has been issued, and more alleged…

How June Lapine Dismantled Hasan Piker’s Image and Forced a Wardrobe Transformation

June Lapine, known widely online as Shoe0468 (or Shoe013),…

Iran's Ghalibaf Declares Persian Gulf Oil Flows For 'All Or None'

Via The Cradle Iranian Parliament Speaker Mohammad Bagher Ghalibaf…

Wage Gains for Bottom 25% of Working Americans Are Up 5.5% – Every Week We See Real Wage Gains”

Treasury Secretary Scott Bessent was on Newsmax‘s “Rob Schmitt…

These Are The World's Safest (And Least Safe) Cities

Doha ranks as the safest major city in the…

Department of Justice Indicts Southern Poverty Law Center on Federal Fraud Charges

In a major federal enforcement action, Acting Attorney General…

US Steps Up Africa Push As China Expands Economic, Security Footprint

Authored by Arthur Zhang via The Epoch Times, The…

CONVERSATION

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted