CISA added six Microsoft vulnerabilities to its Known Exploited Vulnerabilities catalog on February 10, 2026, confirming active exploitation in the wild and triggering mandatory remediation timelines for federal agencies under Binding Operational Directive 22-01.
The additions include CVE-2026-21510, CVE-2026-21513, CVE-2026-21514, CVE-2026-21519, CVE-2026-21525, and CVE-2026-21533. All six affect Microsoft products and were added based on evidence that threat actors are actively leveraging them in attacks against real world targets.
Federal Civilian Executive Branch agencies must remediate these vulnerabilities by the deadline specified in the catalog entry. BOD 22-01 requires agencies to apply vendor provided patches or implement compensating controls within the prescribed timeline, with no exceptions for systems deemed difficult to update.
While KEV catalog entries create binding obligations only for federal agencies, CISA strongly encourages all organizations to prioritize remediation of cataloged vulnerabilities. The presence of a CVE in the KEV catalog indicates confirmed exploitation, not merely theoretical risk, making these entries a high confidence signal for patch prioritization across any environment running affected Microsoft products.