Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Alerts on Active Exploitation of Major Software Vulnerabilities

CISA Alerts on Active Exploitation of Major Software Vulnerabilities

Posted on February 13, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of newly disclosed vulnerabilities in major software, including SolarWinds, Notepad++, and Microsoft. These vulnerabilities have been added to CISA’s Known Exploited Vulnerabilities (KEV) list, highlighting the urgent need for organizations to implement patches.

Details on SolarWinds Vulnerability

The SolarWinds vulnerability, identified as CVE-2025-40536 with a CVSS score of 8.1, was disclosed in late January. This flaw is found in the Web Help Desk (WHD) and allows unauthorized access to restricted functionalities. Horizon3.ai, the entity responsible for uncovering the flaw, noted that it enables attackers to create a valid AjaxProxy instance, potentially leading to remote code execution (RCE) through additional exploits.

Following Microsoft’s recent revelations, CISA has urged federal agencies to patch this vulnerability within three days. Microsoft noted that this flaw might have been exploited as a zero-day in December 2025, alongside another WHD issue, CVE-2025-40551, which was also targeted in similar attacks.

Apple and Notepad++ Vulnerabilities

Also added to the KEV list is CVE-2026-20700, a buffer overflow vulnerability in Apple products. This flaw was addressed with a patch, but it has already been utilized in highly sophisticated attacks. Simultaneously, Notepad++ users are at risk due to CVE-2025-15556, a vulnerability that compromises update integrity verification. This issue arises from a lack of cryptographic checks, allowing attackers to intercept updates and execute arbitrary code.

Reports indicate that the Notepad++ flaw has been exploited by hackers linked to China, specifically the cyberespionage group known as Lotus Blossom, since June 2025. The exploitation involves intercepting update traffic to deploy modified installers.

Microsoft Configuration Manager Vulnerability

Another significant vulnerability, CVE-2024-43468, pertains to Microsoft Configuration Manager. This critical RCE flaw involves an SQL injection vulnerability that does not require user interaction. Although proof-of-concept code has been available for over a year, it has only recently become a focus due to CISA’s warnings.

CISA has mandated that federal agencies apply patches for these vulnerabilities within weeks. This directive underscores the importance of timely updates to mitigate potential threats and secure systems against ongoing cyber risks.

Related discussions have highlighted new updates from tech giants like Intel, AMD, and Microsoft, which have addressed numerous vulnerabilities as part of their regular security updates.

Security Week News Tags:Apple, CISA, Cybersecurity, Exploits, Microsoft, Notepad, Patching, SolarWinds, Vulnerabilities, zero-day

Post navigation

Previous Post: Zimbra Enhances Security with Critical Update
Next Post: Malicious Chrome Extensions Compromise VKontakte Users

Related Posts

Compyl Raises  Million for GRC Platform Compyl Raises $12 Million for GRC Platform Security Week News
Printer Company Procolored Served Infected Software for Months Printer Company Procolored Served Infected Software for Months Security Week News
The Great Disconnect: Unmasking the ‘Two Separate Conversations’ in Security The Great Disconnect: Unmasking the ‘Two Separate Conversations’ in Security Security Week News
Critical Patch Secures OpenClaw AI Against Hijacking Critical Patch Secures OpenClaw AI Against Hijacking Security Week News
RMPocalypse: New Attack Breaks AMD Confidential Computing RMPocalypse: New Attack Breaks AMD Confidential Computing Security Week News
CitrixBleed 2: 100 Organizations Hacked, Thousands of Instances Still Vulnerable CitrixBleed 2: 100 Organizations Hacked, Thousands of Instances Still Vulnerable Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Group Linked to Malware Attacks on Ukraine
  • XWorm RAT Campaign Evades Detection with Excel Exploit
  • UAT-9921 Targets Tech and Finance with VoidLink Malware
  • OpenClaw 2026.2.12 Update Enhances Security with 40+ Fixes
  • StealC Malware Targets Windows via Fake CAPTCHA

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Group Linked to Malware Attacks on Ukraine
  • XWorm RAT Campaign Evades Detection with Excel Exploit
  • UAT-9921 Targets Tech and Finance with VoidLink Malware
  • OpenClaw 2026.2.12 Update Enhances Security with 40+ Fixes
  • StealC Malware Targets Windows via Fake CAPTCHA

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News