IOC Passport
CVE-2026-21509
A CVE identifier referenced in published reporting. It is vulnerability context, not a malicious indicator or feed verdict.
This value remains inside its 90-day contextual reporting window. Current reporting status is separate from verified-feed admission. Archive-cleared or archived does not mean clean, inactive, benign, remediated, resolved, or safe, and this lifecycle does not change current verified-feed admission.
Current verified-feed status
Checking live guard…Article reporting and current malicious-feed admission are evaluated separately.
- First reported
- Last reported
- Article count
- 5
- Admission policy
- Context only
- Research lifecycle
- Current
Article reporting history
These dates are report publication dates, not provider sightings or proof of malicious activity.
CaptiveCrunch Shows Why Travel Wi-Fi Is an Identity Attack Surface
Pawn Storm Deploys PRISMEX Malware Suite Against Ukrainian Defense Supply Chain and NATO Allies
Russian APT Deploys Cat-Themed BadPaw and MeowMeow Malware to Target Ukraine
APT28 Exploited CVE-2026-21513 MSHTML Zero-Day as Attack Vector Before February Patch Tuesday
APT28 Exploits CVE-2026-21509 in Operation Neusploit: Stealing Emails with MiniDoor Backdoor
Related indicators
Observables that appear alongside this one in the same reporting. Co-occurrence can suggest shared infrastructure, but it does not establish common ownership, campaign identity, or actor attribution.
