HIGHVulnerability
Verified
Global

CISA KEV: Microsoft Internet Explorer — Microsoft Internet Explorer Use-After-Free Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Analysis

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Added to CISA Known Exploited Vulnerabilities catalog on 2026-05-20. Remediation due: 2026-06-03.

Indicators of Compromise (1)

CVE (1)
CVE-2010-0806
Source Attribution

Originally published by CISA KEV on May 20, 2026. Verified by: CISA.

Related Threats

MEDIUMVulnerabilityNEW

Slate Valley Unified School District voted not to pay ransom demand; Kairos likely to leak data

The Slate Valley Unified School District in Fair Haven, Vermont, has been responding to a security incident since September 3. On October 2, Kairos threat actors contacted DataBreaches to alert us to the incident and their response to the district’s claim that they believed student data had not been compromised. They were also angry that... Source

DataBreaches.net
CRITICALVulnerability

NVD CRITICAL: CVE-2026-105215 — ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in...

ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, w

CVE-2026-105215
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-105209 — ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorizati...

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and r

CVE-2026-105209
NIST NVD