ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds SolarWinds Web Help Desk, Notepad++, Microsoft Configuration Manager, and Apple devices flaws to its Known Exploited Vulnerabilities catalog

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-43468
Unauthenticated SQL Injection to RCE in Microsoft Configuration Manager

CVE-2024-43468 is a SQL injection flaw (CWE-89) in Microsoft Configuration Manager that Microsoft rates critical (CVSS 3.1: 9.8), with a network attack vector requiring no privileges or user interaction, and it can escalate to remote code execution on affected site infrastructure. An attacker able to reach a vulnerable Configuration Manager component can submit crafted input that injects SQL commands against the underlying database, manipulate it, and gain code execution in the Configuration Manager environment. Affected deployments are the Configuration Manager current branch versions 2403, 2409, and 2503. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog as of 2026-02-12, confirming in-the-wild exploitation; EPSS is very high (82%), and ransomware use is not yet confirmed.

Do: Install the updated Configuration Manager builds for branches 2403, 2409, and 2503 from Microsoft's monthly security update, per the vendor instructions required by the CISA KEV entry; no public PoC or workaround is documented. Prioritize site systems reachable from untrusted networks, since the CVSS vector is network-exploitable without authentication, and federal agencies must apply mitigations under BOD 22-01 within three weeks of the 2026-02-12 KEV addition or discontinue use. While patching, review logs for unexpected SQL activity against Configuration Manager databases to check for signs of exploitation.

9.882% KEV
  • Microsoft Configuration Manager Configuration Manager current branch 2403, 2409, and 2503 (CISA lists Microsoft Configuration Manager broadly)
mass≈100,000+ deployments worldwide (order-of-magnitude estimate)
CVE-2025-15556
Unverified updates in Notepad++ WinGUp updater allow arbitrary code execution

Notepad++ versions prior to 8.8.9, when using the bundled WinGUp updater, download update metadata and installers without cryptographically verifying their integrity (CWE-494). An attacker who can intercept or redirect the updater's network traffic, such as through a man-in-the-middle position or a DNS hijack, can substitute an attacker-controlled installer that the updater then downloads and executes. Successful exploitation yields arbitrary code execution with the privileges of the user running Notepad++, with no attacker credentials or privileges required. Any Windows installation of Notepad++ with the auto-updater in use is affected, and because Notepad++ is one of the most widely used free Windows text editors the potentially exposed population is very large, although practical attacks require control of the victim's update path. CISA added CVE-2025-15556 to the Known Exploited Vulnerabilities catalog on 2026-02-12, and public reporting indicates the hijacked update mechanism was used to deliver targeted malware, confirming exploitation in the wild.

Do: Upgrade to Notepad++ 8.8.9 or later, which adds integrity verification of downloaded updates; this is also the required remediation for federal agencies under CISA BOD 22-01 following the 2026-02-12 KEV listing. Until patched, restrict or monitor hosts' access to the Notepad++ update endpoint and check whether WinGUp recently executed any unexpected installers on systems of interest.

7.72% KEV
  • Notepad++ (notepad-plus-plus) Notepad++ all versions prior to 8.8.9 (Windows, when the bundled WinGUp updater is in use)
masstens of millions of Windows installations (order-of-magnitude estimate)
CVE-2025-40536
Unauthenticated Security Control Bypass in SolarWinds Web Help Desk

SolarWinds Web Help Desk contains a security control bypass (CWE-693) that lets an unauthenticated, remote attacker reach functionality that should be restricted. The flaw is exploitable over the network without credentials or user interaction, which is why it carries a critical 9.8 CVSS 3.1 score. An attacker gains access to restricted features, and reporting indicates the bug has been exploited alongside related Web Help Desk flaws for unauthenticated remote code execution, with attackers installing remote-access tools such as Zoho agents and Velociraptor. Any organization running SolarWinds Web Help Desk is affected, with internet-facing help desk servers at greatest risk. CISA added the issue to its Known Exploited Vulnerabilities catalog on 2026-02-12, confirming active in-the-wild exploitation, and EPSS assigns it an 81.6% probability of exploitation within 30 days (100th percentile).

Do: Upgrade SolarWinds Web Help Desk to the latest vendor release, which also addresses related unauthenticated RCE and authentication-bypass flaws; no fixed version number is given in this data, so follow SolarWinds' advisory for the patched release. Because the bug is under active attack, prioritize patching internet-exposed instances, restrict network access to the help desk console, and hunt for signs of compromise such as unexpected Velociraptor deployments or Zoho remote agents. Federal agencies must apply mitigations per vendor instructions and BOD 22-01 guidance within the required timeframe, or discontinue use of the product if mitigations are unavailable.

9.882% KEV
  • SolarWinds Web Help Desk
moderate≈2,000–5,000 internet-exposed instances; likely tens of thousands of total deployments (estimate)
CVE-2026-20700
Exploited Memory Corruption Flaw in Apple iOS, iPadOS, macOS, tvOS, visionOS, watchOS

CVE-2026-20700 is a memory corruption (buffer overflow) issue in multiple Apple operating systems that Apple addressed through improved state management. The flaw requires a local attack vector: an attacker who already has some memory-write capability on the device — typically obtained via a chained exploit such as a browser or sandbox escape — can leverage this bug to execute arbitrary code. Attackers gain code execution with the privileges of the compromised component, with high impact on confidentiality, integrity, and availability per the CVSS 7.8 (High) score. All users of iPhone, iPad, Mac, Apple TV, Vision Pro, and Apple Watch running versions earlier than the 26.3 updates are affected. Apple reports the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions before iOS 26, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-02-12; related CVEs CVE-2025-14174 and CVE-2025-43529 were issued from the same report.

Do: Update all Apple devices to iOS/iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, and watchOS 26.3 or later; the fix also addresses related CVE-2025-14174 and CVE-2025-43529 from the same report. Federal agencies must meet the KEV/BOD 22-01 deadline by patching per vendor instructions or discontinuing affected device use. Given the targeted, exploit-kit-driven attacks (e.g., DarkSword/Coruna tooling reported in the wild), prioritize updates for high-risk users such as executives, journalists, and activists, and verify fleet-wide OS versions rather than assuming patch compliance.

7.81% KEV
  • Apple iOS (iPhone OS) all versions prior to iOS 26.3
  • Apple iPadOS all versions prior to iPadOS 26.3
  • Apple macOS (Tahoe) all versions prior to macOS Tahoe 26.3
  • +3 more
mass≈1.5–2 billion active Apple devices (Apple's publicly reported active install base), with a large share likely on pre-26.3 versions
Full article453 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 13, 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SolarWinds Web Help Desk, Notepad++, Microsoft Configuration Manager, and Apple devices flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SolarWinds Web Help Desk, Notepad++, Microsoft Configuration Manager, and Apple devices flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the flaws added to the catalog:

  • CVE-2024-43468 (CVSS score 9.8) Microsoft Configuration Manager SQL Injection Vulnerability
  • CVE-2025-15556 (CVSS score 7.7) Notepad++ Download of Code Without Integrity Check Vulnerability
  • CVE-2025-40536 (CVSS score 8.1) SolarWinds Web Help Desk Security Control Bypass Vulnerability
  • CVE-2026-20700 (CVSS score 7.8) Apple Multiple Buffer Overflow Vulnerability

The first flaw added to the catalog is a Microsoft Configuration Manager SQL Injection Vulnerability tracked as CVE-2024-43468. An unauthenticated attacker could send specially crafted requests to the system and trigger unsafe processing, allowing them to execute commands on the server or underlying database.

The second flaw added to the catalog is a Notepad++ Download of Code Without Integrity Check tracked as CVE-2025-15556. Vulnerability. Notepad++ versions before 8.8.9 using WinGUp have a flaw where updates aren’t verified. An attacker intercepting update traffic can make the updater run a malicious installer, allowing arbitrary code execution with the user’s privileges.

The third flaw added to the catalog is a security control bypass vulnerability, tracked as CVE-2025-40536, that could allow an unauthenticated attacker to access certain restricted functionality within Web Help Desk. While more limited in scope than the critical flaws, successful exploitation could still expose sensitive features and weaken the application’s overall security posture.

The last flaw added to the catalog is an Apple Multiple Buffer Overflow Vulnerability tracked as CVE-2026-20700.

This week, Apple released updates for iOS, iPadOS, macOS, watchOS, tvOS, and visionOS to address an actively exploited zero-day tracked as CVE-2026-20700. The flaw is a memory corruption issue in Apple’s Dynamic Link Editor (dyld) that lets attackers execute arbitrary code on vulnerable devices.

Google’s Threat Analysis Group discovered and reported the issue, a circumstance that suggests the flaw may have been exploited by nation-state actors or commercial spyware vendors in attacks in the wild.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by March 5, 2026, except CVE-2025-40536, which must be solved by February 15, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/187937/security/u-s-cisa-adds-solarwinds-web-help-desk-notepad-microsoft-configuration-manager-and-apple-devices-flaws-to-its-known-exploited-vulnerabilities-catalog.html