🟢 CVE-2026-21510

Windows Shell security feature bypass vulnerability with high CVSS score but requires user interaction. Affects primarily client systems with minimal internet-facing deployment likelihood.

← Back to Overview
LOW_RISK
Risk Level
8.8
CVSS Score
NETWORK
Attack Vector
Privilege Escalation
ATT&CK Tactic
T1548 — Abuse Elevation Control Mechanism
ATT&CK Technique
VERY_LOW
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: MEDIUM

Exploitation Method: USER_INTERACTION

CVE Published: 2026-02-10

Added to CISA KEV: 2026-02-10 0 DAY BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-02-10)

Regarding CVE-2026-21510, there is no specific information available about its exploitation, including whether it affects internet-facing applications, evidence of active exploitation, attack vectors, targeted attacks, or its status on the CISA Known Exploited Vulnerabilities (KEV) catalog.

The CISA KEV catalog is a resource that lists vulnerabilities that have been actively exploited in the wild, and organizations are encouraged to use it for vulnerability management prioritization [1][5]. CISA regularly updates this catalog with new vulnerabilities based on evidence of active exploitation [2][3]. However, CVE-2026-21510 is not mentioned in the provided information.

While some vulnerabilities have had exploitation efforts ongoing since specific dates [4], and CISA has added multiple vulnerabilities to its KEV catalog in early 2026 [2][3], there are no details linking CVE-2026-21510 to any of these activities or providing technical details about its exploitability.

Sources

  1. Known Exploited Vulnerabilities Catalog - CISA

    For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catal…

  2. CISA Adds Two Known Exploited Vulnerabilities to Catalog

    CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

  3. CISA Adds One Known Exploited Vulnerability to Catalog

    CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

  4. CISA Updates KEV Catalog with Four Actively Exploited Software...

    CISA added four actively exploited vulnerabilities to its KEV catalog, urging U.S. federal agencies to apply fixes by February 12, 2026.According to CrowdSec, exploitation efforts targeting CVE-2025-68645 have been ongoing since January 14, 2026. There are currently no details on how the other vulne…

  5. Reducing the Significant Risk of Known Exploited Vulnerabilities - CISA

    Learn about the importance of CISA's Known Exploited Vulnerability (KEV) catalog and how to use it to help build a collective resilience across the cybersecurity community.