Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Alerts on Active Exploitation of Major Software Vulnerabilities

CISA Alerts on Active Exploitation of Major Software Vulnerabilities

Posted on February 13, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of newly disclosed vulnerabilities in major software, including SolarWinds, Notepad++, and Microsoft. These vulnerabilities have been added to CISA’s Known Exploited Vulnerabilities (KEV) list, highlighting the urgent need for organizations to implement patches.

Details on SolarWinds Vulnerability

The SolarWinds vulnerability, identified as CVE-2025-40536 with a CVSS score of 8.1, was disclosed in late January. This flaw is found in the Web Help Desk (WHD) and allows unauthorized access to restricted functionalities. Horizon3.ai, the entity responsible for uncovering the flaw, noted that it enables attackers to create a valid AjaxProxy instance, potentially leading to remote code execution (RCE) through additional exploits.

Following Microsoft’s recent revelations, CISA has urged federal agencies to patch this vulnerability within three days. Microsoft noted that this flaw might have been exploited as a zero-day in December 2025, alongside another WHD issue, CVE-2025-40551, which was also targeted in similar attacks.

Apple and Notepad++ Vulnerabilities

Also added to the KEV list is CVE-2026-20700, a buffer overflow vulnerability in Apple products. This flaw was addressed with a patch, but it has already been utilized in highly sophisticated attacks. Simultaneously, Notepad++ users are at risk due to CVE-2025-15556, a vulnerability that compromises update integrity verification. This issue arises from a lack of cryptographic checks, allowing attackers to intercept updates and execute arbitrary code.

Reports indicate that the Notepad++ flaw has been exploited by hackers linked to China, specifically the cyberespionage group known as Lotus Blossom, since June 2025. The exploitation involves intercepting update traffic to deploy modified installers.

Microsoft Configuration Manager Vulnerability

Another significant vulnerability, CVE-2024-43468, pertains to Microsoft Configuration Manager. This critical RCE flaw involves an SQL injection vulnerability that does not require user interaction. Although proof-of-concept code has been available for over a year, it has only recently become a focus due to CISA’s warnings.

CISA has mandated that federal agencies apply patches for these vulnerabilities within weeks. This directive underscores the importance of timely updates to mitigate potential threats and secure systems against ongoing cyber risks.

Related discussions have highlighted new updates from tech giants like Intel, AMD, and Microsoft, which have addressed numerous vulnerabilities as part of their regular security updates.

Security Week News Tags:Apple, CISA, Cybersecurity, Exploits, Microsoft, Notepad, Patching, SolarWinds, Vulnerabilities, zero-day

Post navigation

Previous Post: Zimbra Enhances Security with Critical Update
Next Post: Malicious Chrome Extensions Compromise VKontakte Users

Related Posts

How Software Development Teams Can Securely and Ethically Deploy AI Tools How Software Development Teams Can Securely and Ethically Deploy AI Tools Security Week News
US Calls Reported Threats by Pro-Iran Hackers to Release Trump-Tied Material a ‘Smear Campaign’ US Calls Reported Threats by Pro-Iran Hackers to Release Trump-Tied Material a ‘Smear Campaign’ Security Week News
146,000 Impacted by Delta Dental of Virginia Data Breach 146,000 Impacted by Delta Dental of Virginia Data Breach Security Week News
Supply Chain Attack Hits Checkmarx Jenkins Plugin Supply Chain Attack Hits Checkmarx Jenkins Plugin Security Week News
Chinese Hackers Breached Law Firm Williams & Connolly via Zero-Day Chinese Hackers Breached Law Firm Williams & Connolly via Zero-Day Security Week News
Gladinet CentreStack Flaw Exploited to Hack Organizations Gladinet CentreStack Flaw Exploited to Hack Organizations Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • North Korean IT Workers Exploit AI and Remote Access
  • Data Breach at ShipMonk Risks Trezor Customer Security
  • Windows Zero-Day Exploit Unveiled by Nightmare Eclipse
  • Critical Security Updates for Microsoft Exchange Server
  • July 2026 Cybersecurity M&A: Key Acquisitions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • North Korean IT Workers Exploit AI and Remote Access
  • Data Breach at ShipMonk Risks Trezor Customer Security
  • Windows Zero-Day Exploit Unveiled by Nightmare Eclipse
  • Critical Security Updates for Microsoft Exchange Server
  • July 2026 Cybersecurity M&A: Key Acquisitions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark