Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Alerts on Active Exploitation of Major Software Vulnerabilities

CISA Alerts on Active Exploitation of Major Software Vulnerabilities

Posted on February 13, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of newly disclosed vulnerabilities in major software, including SolarWinds, Notepad++, and Microsoft. These vulnerabilities have been added to CISA’s Known Exploited Vulnerabilities (KEV) list, highlighting the urgent need for organizations to implement patches.

Details on SolarWinds Vulnerability

The SolarWinds vulnerability, identified as CVE-2025-40536 with a CVSS score of 8.1, was disclosed in late January. This flaw is found in the Web Help Desk (WHD) and allows unauthorized access to restricted functionalities. Horizon3.ai, the entity responsible for uncovering the flaw, noted that it enables attackers to create a valid AjaxProxy instance, potentially leading to remote code execution (RCE) through additional exploits.

Following Microsoft’s recent revelations, CISA has urged federal agencies to patch this vulnerability within three days. Microsoft noted that this flaw might have been exploited as a zero-day in December 2025, alongside another WHD issue, CVE-2025-40551, which was also targeted in similar attacks.

Apple and Notepad++ Vulnerabilities

Also added to the KEV list is CVE-2026-20700, a buffer overflow vulnerability in Apple products. This flaw was addressed with a patch, but it has already been utilized in highly sophisticated attacks. Simultaneously, Notepad++ users are at risk due to CVE-2025-15556, a vulnerability that compromises update integrity verification. This issue arises from a lack of cryptographic checks, allowing attackers to intercept updates and execute arbitrary code.

Reports indicate that the Notepad++ flaw has been exploited by hackers linked to China, specifically the cyberespionage group known as Lotus Blossom, since June 2025. The exploitation involves intercepting update traffic to deploy modified installers.

Microsoft Configuration Manager Vulnerability

Another significant vulnerability, CVE-2024-43468, pertains to Microsoft Configuration Manager. This critical RCE flaw involves an SQL injection vulnerability that does not require user interaction. Although proof-of-concept code has been available for over a year, it has only recently become a focus due to CISA’s warnings.

CISA has mandated that federal agencies apply patches for these vulnerabilities within weeks. This directive underscores the importance of timely updates to mitigate potential threats and secure systems against ongoing cyber risks.

Related discussions have highlighted new updates from tech giants like Intel, AMD, and Microsoft, which have addressed numerous vulnerabilities as part of their regular security updates.

Security Week News Tags:Apple, CISA, Cybersecurity, Exploits, Microsoft, Notepad, Patching, SolarWinds, Vulnerabilities, zero-day

Post navigation

Previous Post: Zimbra Enhances Security with Critical Update
Next Post: Malicious Chrome Extensions Compromise VKontakte Users

Related Posts

Law Firms Warned of Silent Ransom Group Attacks Law Firms Warned of Silent Ransom Group Attacks Security Week News
Tens of Thousands of Malicious NPM Packages Distribute Self-Replicating Worm Tens of Thousands of Malicious NPM Packages Distribute Self-Replicating Worm Security Week News
Cyber Insights 2026: Regulations and the Tangled Mess of Compliance Requirements Cyber Insights 2026: Regulations and the Tangled Mess of Compliance Requirements Security Week News
Prometei Botnet Activity Spikes – SecurityWeek Prometei Botnet Activity Spikes – SecurityWeek Security Week News
Honeywell Experion PKS Flaws Allow Manipulation of Industrial Processes Honeywell Experion PKS Flaws Allow Manipulation of Industrial Processes Security Week News
High-Severity Vulnerabilities Patched in Tenable Nessus Agent High-Severity Vulnerabilities Patched in Tenable Nessus Agent Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • North Korean IT Operative’s Elaborate Job Scam Exposed
  • DeepLoad Malware Exploits ClickFix for Credential Theft
  • Server Leak Uncovers TheGentlemen Ransomware Toolkit
  • Iran’s Digital Warfare Tactics: A Comprehensive Analysis
  • CrySome RAT: The Emerging Threat to Windows Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • North Korean IT Operative’s Elaborate Job Scam Exposed
  • DeepLoad Malware Exploits ClickFix for Credential Theft
  • Server Leak Uncovers TheGentlemen Ransomware Toolkit
  • Iran’s Digital Warfare Tactics: A Comprehensive Analysis
  • CrySome RAT: The Emerging Threat to Windows Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark