Security Affairs newsletter Round 561 by Pierluigi Paganini
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-40551 | Unauthenticated Deserialization RCE in SolarWinds Web Help Desk SolarWinds Web Help Desk contains a deserialization of untrusted data flaw (CWE-502) that allows an unauthenticated attacker to reach the vulnerable functionality over the network and have it deserialize attacker-supplied input. By sending crafted serialized data, the attacker triggers remote code execution and can run arbitrary commands on the host machine running Web Help Desk. Successful compromise grants control of the help desk server, and observed intrusions include attackers installing Zoho agents and Velociraptor for post-exploitation. Any organization running the product is affected, particularly instances exposed to the internet; the flaw carries a CVSS 9.8 (critical) score and federal agencies are under a CISA (BOD 22-01) patching deadline. The vulnerability is being actively exploited in the wild and was added to the CISA KEV catalog on 2026-02-03, with an EPSS probability of 83.6% that it will be exploited within 30 days. Do: Upgrade Web Help Desk to the latest patched release per the SolarWinds security advisory (the source data does not specify a fixed version number), and follow BOD 22-01 mitigations or discontinue use if mitigation is not possible, noting the federal patching deadline. Until patched, restrict internet-facing access to the Web Help Desk server. Check hosts for post-exploitation artifacts reported in the wild, such as unexpected Zoho agent installations and Velociraptor, and review logs for unauthenticated requests targeting the application. | 9.8 | 84% | KEV |
| large≈ tens of thousands of on-premises deployments worldwide (order of magnitude: 10,000–100,000 systems), an estimate | |
| CVE-2025-8088 | WinRAR Path Traversal (CVE-2025-8088) Enables Arbitrary Code Execution A path traversal flaw (CWE-35) in the Windows version of WinRAR allows attackers to achieve arbitrary code execution by delivering a specially crafted archive file that writes outside the expected location when it is opened or processed. Because the CVSS 4.0 vector indicates a local attack requiring user interaction, victims are typically infected by extracting or previewing a malicious archive received via phishing, a malicious download, or another delivery channel. A successful attacker gains the privileges of the user running WinRAR, providing an initial foothold that has been used for both espionage and ransomware operations. Anyone running the Windows version of WinRAR — one of the most widely deployed Windows desktop utilities — is affected, and CPE data additionally lists dtSearch as an affected vendor. Exploitation is confirmed in the wild by nation-state actors (e.g., the China-linked Amaranth-Dragon group per related reporting) and criminal actors including ransomware operators; the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-12 and carries a near-maximal 94.6% EPSS score. Do: Update WinRAR to the latest patched release from RARLAB on all Windows endpoints, prioritizing remediation per CISA KEV and BOD 22-01 requirements, and verify that dtSearch deployments bundling the affected component are also updated. Because exploitation requires a user to open or extract a crafted archive, warn users to treat unexpected archive files delivered by email or download with suspicion. Given confirmed ransomware use, hunt across user workstations — not just exposed servers — for suspicious archive-based infections and confirm the patched WinRAR version is installed. | 8.4 | 95% | KEV ransomware |
| masshundreds of millions of Windows users/devices (est.; RARLAB has historically claimed user counts in the hundreds of millions) | |
| CVE-2026-24858 | FortiCloud SSO Authentication Bypass Across Multiple Fortinet Products CVE-2026-24858 is an authentication bypass (CWE-288) in FortiCloud single sign-on that lets an attacker who owns a FortiCloud account with any registered device log in to other customers' Fortinet devices that have FortiCloud SSO authentication enabled. It affects a wide range of 7.x/8.x builds of FortiOS, FortiProxy, FortiWeb, FortiAnalyzer, FortiManager, FortiNAC-F, and the Siemens RUGGEDCOM APE 1808. An attacker gains unauthorized access to devices registered to other accounts, and related reporting describes FortiGate devices being exploited to breach networks and steal service account credentials. Any organization running an affected build with FortiCloud SSO enabled is exposed. Exploitation is confirmed in the wild: CISA added the flaw to the KEV catalog on 2026-01-27 and Fortinet patched it after active FortiOS SSO exploitation was detected, and EPSS assigns an 86.1% probability of exploitation within 30 days. Do: Upgrade all affected Fortinet products to the fixed releases specified in Fortinet's PSIRT advisory for CVE-2026-24858; as an interim mitigation, disable FortiCloud SSO authentication on affected devices and audit which devices are registered to your FortiCloud account. Review device logs for unexpected administrative logins or signs of service-account credential theft on FortiGate, and federal agencies must apply mitigations per BOD 22-01 (including CISA's cloud services guidance) or discontinue use of the product. | 9.8 | 86% | KEV |
| masshundreds of thousands of devices potentially affected (Fortinet's FortiGate install base is in the millions and public internet scans have long shown hundreds… |
Full article729 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
February 02, 2026

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press – Newsletter
Nike Probes Potential Breach After Threat From Hacking Group
Crunchbase Confirms Data Breach After Hacking Claims
ShinyHunters claim hacks of Okta, Microsoft SSO accounts for data theft
Who Operates the Badbox 2.0 Botnet?
Retro Phishing: Basic Auth URLs Make a Comeback in Japan
Notorious Russia-based RAMP cybercrime forum apparently seized by FBI
Co-Creator of Dark Web Marketplace Pleads Guilty in Chicago to Drug Conspiracy
Former Google Engineer Found Guilty Of Economic Espionage And Theft Of Confidential AI Technology
Malware
Android Trojan Campaign Uses Hugging Face Hosting for RAT Payload Delivery
Malicious Chrome Extension Performs Hidden Affiliate Hijacking
Re-Evaluating Android Malware Detection: Tabular Features, Vision Models, and Ensembles
Hacking
Hands-Free Lockpicking: Critical Vulnerabilities in dormakaba’s Physical Access Control System
Microsoft patches actively exploited Office zero-day vulnerability
Resurgence of a multi‑stage AiTM phishing and BEC campaign abusing SharePoint
Over 6,000 SmarterMail servers exposed to automated hijacking attacks
PackageGate: 6 Zero-Days in JS Package Managers But NPM Won’t Act
Fortinet Confirms Active FortiCloud SSO Bypass on Fully Patched FortiGate Firewalls
CVE-2025-40551: Another Solarwinds Web Help Desk Deserialization Issue
Intelligence and Information Warfare
KONNI Adopts AI to Generate PowerShell Backdoors
Weaponized in China, Deployed in India: The SyncFuture Espionage Targeted Campaign
Inside a Multi-Stage Windows Malware Campaign
Operation DupeHike : UNG0902 targets Russian employees with DUPERUNNER and AdaptixC2
WhatsApp’s Latest Privacy Protection: Strict Account Settings
PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups
Space Capabilities to Support Military Operations in the European Theatre
Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088
Why a gradual move away from US tech is a good idea
ELECTRUM: Cyber Attack on Poland’s Electric System 2025
Energy Sector Incident Report – 29 December 2025
Dissecting UAT-8099: New persistence mechanisms and regional focus
Cybersecurity
Defending the 2026 Milano Cortina Winter Games
AI-Powered Disinformation Swarms Are Coming for Democracy
No Place Like Home Network: Disrupting the World’s Largest Residential Proxy Network
Informant told FBI that Jeffrey Epstein had a ‘personal hacker’
US Has Investigated Claims WhatsApp Chats Aren’t Private
Thousands more Oregon residents learn their health data was stolen in TriZetto breach
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
you might also like
leave a comment
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/187524/security/security-affairs-newsletter-round-561-by-pierluigi-paganini-international-edition.html