U.S. CISA adds Microsoft Office and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog

3 Min Read

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Office and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Microsoft Office and Microsoft Windows flaws to its Known Exploited Vulnerabilities (KEV) catalog.

- Advertisement -

Below are the flaws added to the catalog:

  • CVE-2026-21510 Microsoft Windows Shell Protection Mechanism Failure Vulnerability
  • CVE-2026-21513 Microsoft MSHTML Framework Security Feature Bypass Vulnerability
  • CVE-2026-21514 Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability
  • CVE-2026-21519 Microsoft Windows Type Confusion Vulnerability
  • CVE-2026-21525 Microsoft Windows NULL Pointer Dereference Vulnerability
  • CVE-2026-21533 Windows Remote Desktop Services Elevation of Privilege Vulnerability 

This week, Microsoft Patch Tuesday security updates for February 2026 fixed 58 new security flaws across Windows, Office, Azure, Edge, Exchange, Hyper-V, WSL, and other components, rising to 62 CVEs when third-party updates are included. Six flaws addressed this month are actively exploited in the wild, three of them publicly known.


What do you think? Post a comment.


Below is the description of the vulnerabilities addressed by the IT giant and that CISA added to the catalog:

- Advertisement -

EXPLORE MORE

ApolloMD data breach impacts 626,540 people

A May 2025 cyberattack on ApolloMD exposed the personal data of over…

First Secondary Sanctions Applied: US Blocks Egyptian Bank From Accessing Dollars Over 'Iran Ties'

The US Treasury Department on Friday unveiled its first 'secondary' Iran sanctions…

Pro-Russian group Noname057(16) launched DDoS attacks on Milano Cortina 2026 Winter Olympics

Italy stopped Russian-linked cyberattacks targeting Foreign Ministry offices and Winter Olympics websites…

Uprising In Ceuta: Locals Have Had Enough Of Migrant Invasion

Authored by Steve Watson via Modernity News,In the complete absence of any…

Wanted: Suspect for Theft of a Dog in the 35th District [UPDATE]

***THE VICTIM’S DOG HAS BEEN RETURNED BY A GOOD SAMARITAN AND THIS…

The ‘Russian Bounties’ Hoax: The Fake News Story That Promoted Michael Schwirtz to the Top

In June 2020, The New York Times delivered what appeared to be…

  • CVE-2026-21510 (CVSS score of 7.5 – High)
    A Windows SmartScreen and Shell prompt bypass that allows attackers to evade security warnings by tricking users into opening a crafted malicious link or shortcut file.
  • CVE-2026-21513 (CVSS score of 8.8 – High)
    An Internet Explorer security control bypass that can lead to code execution when a victim opens a malicious HTML page or LNK file.
  • CVE-2026-21514 (CVSS score of 8.1 – High)
    A Microsoft 365 and Office flaw that bypasses OLE security mitigations, enabling malicious activity when a specially crafted Office document is opened.
  • CVE-2026-21519 (CVSS score of 7.8 – High)
    A Windows Desktop Window Manager vulnerability that enables local privilege escalation and elevated system access.
  • CVE-2026-21525 (CVSS score of 6.5 – Medium)
    A Windows Remote Access Connection Manager bug that can be abused by a local attacker to cause a denial-of-service condition.
  • CVE-2026-21533 (CVSS score of 8.8 – High)
    A Windows Remote Desktop Services vulnerability that allows attackers to escalate privileges to SYSTEM.

Microsoft labeled CVE-2026-21510, CVE-2026-21514 and CVE-2026-21513 as “publicly disclosed”.

The company credited Google Threat Intelligence Group, its internal security teams, and an anonymous researcher for discovering CVE-2026-21510 and CVE-2026-21514, while Microsoft and GTIG reported the vulnerability CVE-2026-21513.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by March 3rd, 2026.

Pierluigi Paganini



Share This Article

US Steps Up Africa Push As China Expands Economic, Security Footprint

Authored by Arthur Zhang via The Epoch Times, The…

Zionism and the Ottoman Empire: The Final Step to Conquering Palestine

The final step, which lasted until the fall of…

China backs Cuba after Trump says island ‘will fall’

Beijing has vowed to support Havana against external interference…

Battle of Trafalgar: Strategic Necessity or Aggressive Overreach?

CAPE TRAFALGAR — On October 21, 1805, 27 British…

Why Russia Issued an Arrest Warrant for a Gay British Agitator

Caolan Robertson is an British YouTube video maker, amateur…

Turkey Recruits Trump Insiders For New Washington Lobbying Push

Via Middle East Eye The Turkish government hired a lobbying firm…

Canada MAID Program: Truth About the 16,000 Assisted Deaths

A striking narrative has taken center stage in global…

SAUDI DEFENSE PAPER TIGER: FOREIGN CONTRACTORS AND INTEL LEAKS IN YEMEN

RIYADH — As geopolitical volatility escalates across the Arabian…

CONVERSATION

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted