CVE-2026-21265
Microsoft Windows 10 21H2 ≤ 10.0.19044.6809
Raw vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2026-21265 is a medium-severity Reliance on Component That is Not Updateable (CWE-1329) vulnerability in Microsoft Windows 10 21H2. Its CVSS base score is 6.4 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Privilege Escalation (T1068); ranked in the top 40% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SA-22 (Unsupported System Components) — see the control section below for these in your framework.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-2100
Vulnerability Data
Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing security fixes…
more
related to Windows boot manager or Secure Boot. The operating system’s certificate update protection mechanism relies on firmware components that might contain defects, which can cause certificate trust updates to fail or behave unpredictably. This leads to potential disruption of the Secure Boot trust chain and requires careful validation and deployment to restore intended security guarantees. Certificate Authority (CA) Location Purpose Expiration Date Microsoft Corporation KEK CA 2011 KEK Signs updates to the DB and DBX 06/24/2026 Microsoft Corporation UEFI CA 2011 DB Signs 3rd party boot loaders, Option ROMs, etc. 06/27/2026 Microsoft Windows Production PCA 2011 DB Signs the Windows Boot Manager 10/19/2026 For more information see this CVE and Windows Secure Boot certificate expiration and CA updates.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Replacing components when vendor support ends directly stops reliance on non-updateable parts that cannot receive patches.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Directly addresses replacing or removing software that cannot be maintained via updates or patches.
Directly addresses replacing hardware components that lack needed security capabilities or cannot be updated.
Lifecycle management explicitly requires planning for updates or replacement of components that cannot be patched.
Supplier risk assessment can identify non-updateable components before acquisition but does not prevent their use inside the product.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Supplier agreements can stipulate patchability or end-of-life support, yet the weakness is rooted in product architecture rather than contractual clauses.
ICT supply-chain management can influence component selection toward maintainable ones, but does not guarantee technical updateability.
Supplier-relationship controls can require vendors to provide updateable components, but do not directly mandate component design.
Secure-SDLC practices encourage selection of maintainable components, but the weakness may still arise from third-party or legacy choices.
Change-management processes can plan for component replacement, yet cannot eliminate the inherent non-updateability of an already-deployed component.
Vulnerability-management processes can detect and drive replacement of non-updateable components, but cannot retroactively make them patchable.