Monthly Vuln Summary 2026-02 (28)

In-the-Wild CVE Review · 2026-02

28 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).

本月收录

  • CVE-2022-20775 — 0.0 — Cisco SD-WAN — Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands withi… [KEV]
  • CVE-2026-20127 — 0.0 — Cisco Catalyst SD-WAN Controller and Manager — Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an … [KEV]
  • CVE-2026-25108 — 0.0 — Soliton Systems K.K FileZen — Soliton Systems K.K FileZen contains an OS command injection vulnerability when an user logs-in to the affected product and sends a specially crafted HTTP request. [KEV]
  • CVE-2025-49113 — 0.0 — Roundcube Webmail — RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not va… [KEV]
  • CVE-2025-68461 — 0.0 — Roundcube Webmail — RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document. [KEV]
  • CVE-2021-22175 — 0.0 — GitLab GitLab — GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled. [KEV]
  • CVE-2026-22769 — 0.0 — Dell RecoverPoint for Virtual Machines (RP4VMs) — Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized acc… [KEV]
  • CVE-2020-7796 — 0.0 — Synacor Zimbra Collaboration Suite — Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery vulnerability if WebEx zimlet installed and zimlet JSP is enabled. [KEV]
  • CVE-2024-7694 — 0.0 — TeamT5 ThreatSonar Anti-Ransomware — TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous type vulnerability. ThreatSonar Anti-Ransomware does not properly validate the content of … [KEV]
  • CVE-2008-0015 — 0.0 — Microsoft Windows — Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. Wh… [KEV]
  • CVE-2026-2441 — 0.0 — Google Chromium — Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability co… [KEV]
  • CVE-2026-1731 — 0.0 — BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) — BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attac… [KEV] [RANSOMWARE]
  • CVE-2026-20700 — 0.0 — Apple Multiple Products — Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow an attacker with mem… [KEV]
  • CVE-2024-43468 — 0.0 — Microsoft Configuration Manager — Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the t… [KEV]
  • CVE-2025-15556 — 0.0 — Notepad++ Notepad++ — Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to d… [KEV]
  • CVE-2025-40536 — 0.0 — SolarWinds Web Help Desk — SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality. [KEV]
  • CVE-2026-21513 — 0.0 — Microsoft Windows — Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. [KEV]
  • CVE-2026-21525 — 0.0 — Microsoft Windows — Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally. [KEV]
  • CVE-2026-21510 — 0.0 — Microsoft Windows — Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. [KEV]
  • CVE-2026-21533 — 0.0 — Microsoft Windows — Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally. [KEV]
  • CVE-2026-21519 — 0.0 — Microsoft Windows — Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally. [KEV]
  • CVE-2026-21514 — 0.0 — Microsoft Office — Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally. [KEV]
  • CVE-2025-11953 — 0.0 — React Native Community CLI — React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server … [KEV]
  • CVE-2026-24423 — 0.0 — SmarterTools SmarterMail — SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMai… [KEV] [RANSOMWARE]
  • CVE-2021-39935 — 0.0 — GitLab Community and Enterprise Editions — GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the C… [KEV]
  • CVE-2025-64328 — 0.0 — Sangoma FreePBX ** — Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a post-authentication command injection by an authenticated known user via the … [KEV]**
  • CVE-2019-19006 — 0.0 — Sangoma FreePBX — Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access services provided by the F… [KEV]
  • CVE-2025-40551 — 0.0 — SolarWinds Web Help Desk — SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the h… [KEV]

Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.