Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Alerts on Active Exploitation of Major Software Vulnerabilities

CISA Alerts on Active Exploitation of Major Software Vulnerabilities

Posted on February 13, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of newly disclosed vulnerabilities in major software, including SolarWinds, Notepad++, and Microsoft. These vulnerabilities have been added to CISA’s Known Exploited Vulnerabilities (KEV) list, highlighting the urgent need for organizations to implement patches.

Details on SolarWinds Vulnerability

The SolarWinds vulnerability, identified as CVE-2025-40536 with a CVSS score of 8.1, was disclosed in late January. This flaw is found in the Web Help Desk (WHD) and allows unauthorized access to restricted functionalities. Horizon3.ai, the entity responsible for uncovering the flaw, noted that it enables attackers to create a valid AjaxProxy instance, potentially leading to remote code execution (RCE) through additional exploits.

Following Microsoft’s recent revelations, CISA has urged federal agencies to patch this vulnerability within three days. Microsoft noted that this flaw might have been exploited as a zero-day in December 2025, alongside another WHD issue, CVE-2025-40551, which was also targeted in similar attacks.

Apple and Notepad++ Vulnerabilities

Also added to the KEV list is CVE-2026-20700, a buffer overflow vulnerability in Apple products. This flaw was addressed with a patch, but it has already been utilized in highly sophisticated attacks. Simultaneously, Notepad++ users are at risk due to CVE-2025-15556, a vulnerability that compromises update integrity verification. This issue arises from a lack of cryptographic checks, allowing attackers to intercept updates and execute arbitrary code.

Reports indicate that the Notepad++ flaw has been exploited by hackers linked to China, specifically the cyberespionage group known as Lotus Blossom, since June 2025. The exploitation involves intercepting update traffic to deploy modified installers.

Microsoft Configuration Manager Vulnerability

Another significant vulnerability, CVE-2024-43468, pertains to Microsoft Configuration Manager. This critical RCE flaw involves an SQL injection vulnerability that does not require user interaction. Although proof-of-concept code has been available for over a year, it has only recently become a focus due to CISA’s warnings.

CISA has mandated that federal agencies apply patches for these vulnerabilities within weeks. This directive underscores the importance of timely updates to mitigate potential threats and secure systems against ongoing cyber risks.

Related discussions have highlighted new updates from tech giants like Intel, AMD, and Microsoft, which have addressed numerous vulnerabilities as part of their regular security updates.

Security Week News Tags:Apple, CISA, Cybersecurity, Exploits, Microsoft, Notepad, Patching, SolarWinds, Vulnerabilities, zero-day

Post navigation

Previous Post: Zimbra Enhances Security with Critical Update
Next Post: Malicious Chrome Extensions Compromise VKontakte Users

Related Posts

Phishers Abuse SharePoint in New Campaign Targeting Energy Sector Phishers Abuse SharePoint in New Campaign Targeting Energy Sector Security Week News
In Other News: Iranian Ships Hacked, Verified Android Developers, AI Used in Attacks In Other News: Iranian Ships Hacked, Verified Android Developers, AI Used in Attacks Security Week News
Data Breach at Dutch Carrier Odido Affects Millions Data Breach at Dutch Carrier Odido Affects Millions Security Week News
Critical Wing FTP Server Vulnerability Exploited Critical Wing FTP Server Vulnerability Exploited Security Week News
Chrome 142 Update Patches High-Severity Flaws Chrome 142 Update Patches High-Severity Flaws Security Week News
Virtual Event Today: Attack Surface Management Summit Virtual Event Today: Attack Surface Management Summit Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • StealC Malware Targets Windows via Fake CAPTCHA
  • Google Tackles AI Threats, Disney Faces Privacy Fine
  • Malicious Chrome Extensions Compromise VKontakte Users
  • CISA Alerts on Active Exploitation of Major Software Vulnerabilities
  • Zimbra Enhances Security with Critical Update

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • StealC Malware Targets Windows via Fake CAPTCHA
  • Google Tackles AI Threats, Disney Faces Privacy Fine
  • Malicious Chrome Extensions Compromise VKontakte Users
  • CISA Alerts on Active Exploitation of Major Software Vulnerabilities
  • Zimbra Enhances Security with Critical Update

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News