February 2026 CVE Landscape: 13 Critical Vulnerabilities Mark 43% Drop from January
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-20775 | Path Traversal Privilege Escalation in Cisco SD-WAN Software CLI CVE-2022-20775 is a path traversal and improper access control flaw (CWE-22/CWE-25) in the CLI of Cisco SD-WAN Software that allows an authenticated, local attacker to gain elevated privileges. An attacker triggers it by running a maliciously crafted command in the application CLI, abusing weak access controls on CLI commands. A successful exploit yields arbitrary command execution as the root user, giving full control of the affected SD-WAN component. Organizations running Cisco SD-WAN / Catalyst SD-WAN components — SD-WAN Manager, vBond Orchestrator, vSmart Controller, and vEdge Cloud routers — are affected. The flaw is now being actively exploited: it was added to the CISA KEV catalog on 2026-02-25, prompting CISA Emergency Directive 26-03 and joint Five Eyes 'Hunt & Hardening' guidance, a public proof-of-concept exists, and EPSS estimates a 12.5% chance of exploitation within 30 days (96th percentile). Do: Upgrade affected SD-WAN components — Catalyst SD-WAN Manager, vBond Orchestrator, vSmart Controller, and vEdge Cloud — to the fixed releases listed in Cisco advisory cisco-sa-sd-wan-priv-E6e8tEdF, as there are no workarounds. Restrict CLI access to trusted administrators, review local accounts for unexpected additions or changes, and hunt for signs of compromise per CISA Emergency Directive 26-03 and CISA's Hunt & Hardening Guidance for Cisco SD-WAN Devices. If patched software or cloud-service mitigations are unavailable, follow BOD 22-01 guidance and consider discontinuing use of the affected components. | 7.8 | 12% | KEV PoC |
| largeon the order of tens of thousands of SD-WAN controller and edge deployments (10k–100k systems) | |
| CVE-2025-15556 | Unverified updates in Notepad++ WinGUp updater allow arbitrary code execution Notepad++ versions prior to 8.8.9, when using the bundled WinGUp updater, download update metadata and installers without cryptographically verifying their integrity (CWE-494). An attacker who can intercept or redirect the updater's network traffic, such as through a man-in-the-middle position or a DNS hijack, can substitute an attacker-controlled installer that the updater then downloads and executes. Successful exploitation yields arbitrary code execution with the privileges of the user running Notepad++, with no attacker credentials or privileges required. Any Windows installation of Notepad++ with the auto-updater in use is affected, and because Notepad++ is one of the most widely used free Windows text editors the potentially exposed population is very large, although practical attacks require control of the victim's update path. CISA added CVE-2025-15556 to the Known Exploited Vulnerabilities catalog on 2026-02-12, and public reporting indicates the hijacked update mechanism was used to deliver targeted malware, confirming exploitation in the wild. Do: Upgrade to Notepad++ 8.8.9 or later, which adds integrity verification of downloaded updates; this is also the required remediation for federal agencies under CISA BOD 22-01 following the 2026-02-12 KEV listing. Until patched, restrict or monitor hosts' access to the Notepad++ update endpoint and check whether WinGUp recently executed any unexpected installers on systems of interest. | 7.7 | 2% | KEV |
| masstens of millions of Windows installations (order-of-magnitude estimate) | |
| CVE-2026-1731 | Pre-Authentication OS Command Injection RCE in BeyondTrust Remote Support and PRA BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical (CVSS 4.0: 9.9) pre-authentication operating system command injection vulnerability (CWE-78). By sending specially crafted requests to the appliance, an unauthenticated remote attacker can execute operating system commands in the context of the site user, gaining code execution without credentials or user interaction. Any organization running RS or PRA appliances that are reachable from the internet, which is their typical deployment mode for remote support and privileged access, is affected. Exploitation is active: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-13 with known ransomware use, carries an EPSS of 89.5% (100th percentile), has a public proof-of-concept, and press coverage links the newly patched BeyondTrust RCE to fast-moving ransomware activity (Storm-1175). BeyondTrust has released fixes, so unpatched, internet-exposed instances should be treated as high-priority compromise targets. Do: Upgrade all internet-exposed Remote Support and Privileged Remote Access appliances to the fixed releases in BeyondTrust's security advisory immediately, per the CISA KEV required action (apply vendor mitigations or discontinue use if mitigation is unavailable). Until patched, restrict network access to the appliance and review appliance/web logs for suspicious unauthenticated requests, given known ransomware exploitation and the availability of a public proof-of-concept. | 9.9 | 90% | KEV ransomware PoC |
| largeon the order of tens of thousands of internet-exposed RS/PRA appliance instances worldwide | |
| CVE-2026-20127 | Authentication Bypass in Cisco Catalyst SD-WAN Controller, Manager, Validator A flaw in the peering authentication mechanism of Cisco Catalyst SD-WAN Controller (formerly vSmart), Manager (formerly vManage), and Validator (formerly vBond) allows an unauthenticated, remote attacker to bypass authentication by sending crafted requests to an affected system. A successful exploit grants the attacker access as an internal, high-privileged, non-root user on the SD-WAN Controller, from which they can reach NETCONF and manipulate the network configuration of the entire SD-WAN fabric. Any organization operating these Cisco SD-WAN control-plane components is affected, and the critical CVSS 10.0 score reflects full network scope with no privileges or user interaction required. The flaw is confirmed exploited in the wild: CISA added it to the KEV on 2026-02-25, Cisco has confirmed active exploitation (including a compromise of a communications service provider), and Five Eyes allies have issued an active-exploitation warning, with EPSS at 88.2% (100th percentile). Do: Upgrade affected Catalyst SD-WAN Controller, Manager, and Validator components per Cisco's PSIRT advisory (fixed versions are not specified in this data), and prioritize patching given confirmed in-the-wild exploitation. Follow CISA Emergency Directive 26-03 and the CISA Hunt & Hardening Guidance for Cisco SD-WAN Devices: hunt for compromise indicators such as unexpected high-privileged non-root logins and unauthorized NETCONF configuration changes, and restrict internet exposure of SD-WAN management interfaces. Where mitigations are unavailable, adhere to applicable BOD 22-01 cloud guidance or discontinue use of the product. | 10.0 | 88% | KEV |
| large≈10,000–100,000 controller/manager/validator deployments across enterprise and service-provider SD-WAN fabrics (Cisco SD-WAN is a market-leading enterprise… | |
| CVE-2026-21513 +1 in the same advisory: …21533 | MSHTML Security Feature Bypass in Windows Exploited in the Wild (CVE-2026-21513) CVE-2026-21513 is a protection mechanism failure (CWE-693) in Microsoft's MSHTML framework, the legacy HTML rendering engine built into Windows and hosted by browsers, Office, and countless applications that display web content. An unauthorized attacker can exploit it over a network to bypass a Windows security feature; the CVSS vector requires user interaction (UI:R), consistent with delivery via a malicious link or document whose content is rendered through MSHTML. Although classified as a security-feature bypass, the vendor-scored impact is high for confidentiality, integrity, and availability (C:H/I:H/A:H), indicating significant downstream effect when chained with other techniques. All supported Windows client and server releases are in scope, from Windows 10 1607 through Windows 11 25H2 and Windows Server 2012 through Windows Server 2022 23H2. The flaw is being actively exploited: CISA added it to the KEV catalog on 2026-02-10, Microsoft confirmed in-the-wild exploitation, and public reporting ties exploitation to APT28 ahead of the February 2026 Patch Tuesday; EPSS assigns a 15.6% probability of exploitation within 30 days (97th percentile). Do: Apply Microsoft's February 2026 Windows security updates to all in-scope Windows 10, Windows 11, and Windows Server versions as soon as possible; the flaw is KEV-listed and confirmed exploited in the wild (reporting ties it to APT28), making patching a priority even though ransomware use is not yet confirmed. Because the vector requires user interaction and MSHTML is reached through rendered content, strengthen email and web-lure defenses and hunt for APT28 activity on unpatched hosts; US federal agencies must apply vendor mitigations per BOD 22-01 or discontinue use if mitigations are unavailable. | 8.8 group max | 16% | KEV |
| masshundreds of millions of Windows devices and servers (effectively the entire supported Windows install base, >1 billion devices worldwide) | |
| CVE-2026-22769 | Hard-coded credentials in Dell RecoverPoint for Virtual Machines allow root OS access Dell RecoverPoint for Virtual Machines (RP4VMs) versions prior to 6.0.3.1 HF1 contain hard-coded credentials (CWE-798) for the appliance's underlying operating system. An unauthenticated remote attacker who knows the hard-coded credential can authenticate over the network with no user interaction and gain root-level access and persistence on the underlying OS — beyond just the RecoverPoint application — which is why the flaw scores a maximum CVSS of 10.0 with scope changed. Any organization running an affected RP4VMs release is exposed, with risk highest where appliance management interfaces are reachable from broader networks. The vulnerability is confirmed exploited in the wild: it was added to CISA's KEV catalog on 2026-02-18, and reporting indicates China-linked actors exploited it as a zero-day since at least 2024, prompting an emergency federal patch directive; related coverage ties the activity to the China-linked VerdantBamboo actor deploying BRICKSTORM-family backdoors on appliances. Do: Upgrade all RP4VMs appliances to 6.0.3.1 HF1 or apply Dell's published remediations immediately — federal agencies must patch per BOD 22-01 by the KEV deadline (reported as 'by Saturday'). Because exploitation has occurred since at least 2024, treat deployed appliances as potentially compromised: review the underlying OS for unexpected accounts, modified services, and root persistence, and restrict the appliance's management/replication network reachability until patched. | 10.0 | 13% | KEV |
| moderate≈ tens of thousands of appliances worldwide (estimated from deployment patterns; internet-exposed count unknown) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | cdncheck.it.com | C2 infrastructure: 45[.]76[.]155[.]202, 45[.]77[.]31[.]210, cdncheck[.]it[.]com, safe-dns[.]it[.]com, 95[.]179[.]213[.]0 Detection reso |
| domain | safe-dns.it.com | [.]76[.]155[.]202, 45[.]77[.]31[.]210, cdncheck[.]it[.]com, safe-dns[.]it[.]com, 95[.]179[.]213[.]0 Detection resources: Insikt Group c |
| domain | temp.sh | dobe\Scripts\ Block or alert on curl.exe uploading files to temp[.]sh Known C2 infrastructure: 45[.]76[.]155[.]202, 45[.]77[.]3 |
| domain | wellnesscaremed.com | igation flow. The .lnk initiates network communication with wellnesscaremed[.]com as part of APT28's multistage payload delivery. SHA256 fo |
| sha256 | 4d4aec6120290e21778c1b14c94aa6ebff3b0816fb6798495dc2eae165db4566 | 26, 2026 Hunt for the malicious update.exe sample (SHA256: 4d4aec6120290e21778c1b14c94aa6ebff3b0816fb6798495dc2eae165db4566) in your environment Monitor for GUP.exe spawning unexpecte |
| sha256 | aefd15e3c395edd16ede7685c6e97ca0350a702ee7c8585274b457166e86b1fa | age payload delivery. SHA256 for document.doc.LnK.download: aefd15e3c395edd16ede7685c6e97ca0350a702ee7c8585274b457166e86b1fa Why this matters: APT28's use of a weaponized .lnk file exp |
| url | https://45[ | ader, which retrieved a Cobalt Strike Beacon shellcode from hxxps://45[.]77[.]31[.]210/users/admin and executed it. Chain 2 (Septem |
Full article1,861 words · extracted from recordedfuture.com · click to collapse
February 2026 saw a 43% decrease in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 13 vulnerabilities requiring immediate remediation, down from 23 in January 2026. All 13 carried a ‘Very Critical’ Recorded Future Risk Score.
What security teams need to know:
- Microsoft dominates: Six of 13 vulnerabilities affected Microsoft products, accounting for 46% of February's findings; all were added to CISA's KEV catalog on the same day
- Supply-chain attack on Notepad++: Lotus Blossom, a suspected China state-sponsored threat actor, exploited CVE-2025-15556 to hijack Notepad++'s update channel and deliver a Cobalt Strike Beacon and the Chrysalis backdoor
- APT28 exploits MSHTML flaw: The Russian state-sponsored group leveraged CVE-2026-21513 via malicious Windows Shortcut files for multi-stage payload delivery
- Public exploits available: Four of 13 vulnerabilities have publicly available proof-of-concept code; an alleged exploit for a fifth is being advertised for sale
Bottom line: Despite a 43% drop in volume, February's vulnerabilities include named threat actor exploitation and five RCE-enabling flaws, making prioritized, intelligence-driven remediation as important as ever.
Quick Reference: February 2026 Vulnerability Table
All 13 vulnerabilities below were actively exploited in February 2026.
#
Vulnerability
Risk
Score
Affected Vendor/Product
Vulnerability Type/Component
Public PoC
1
99
Notepad++
CWE-494 (Download of Code Without Integrity Check)
2
99
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))
3
99
Microsoft Windows
CWE-693 (Protection Mechanism Failure)
No
4
99
Microsoft Windows
CWE-693 (Protection Mechanism Failure)
No
5
99
Microsoft Office
CWE-807 (Reliance on Untrusted Inputs in a Security Decision)
No
6
99
Microsoft Windows
CWE-843 (Access of Resource Using Incompatible Type ('Type Confusion'))
No
7
99
Microsoft Windows
CWE-476 (NULL Pointer Dereference)
No
8
99
Microsoft Windows
CWE-269 (Improper Privilege Management)
*Yes
9
99
Apple iOS, macOS, tvOS, watchOS, and visionOS
CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)
No
10
99
Soliton Systems K.K. FileZen
CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))
No
11
99
Google Chromium
CWE-416 (Use After Free)
12
99
Dell RecoverPoint for Virtual Machines (RP4VMs)
CWE-798 (Use of Hard-coded Credentials)
No
13
99
Cisco Catalyst SD-WAN Controller and Manager
CWE-287 (Improper Authentication)
Table 1: List of vulnerabilities that were actively exploited in February based on Recorded Future data. *An alleged exploit for CVE-2026-21533 is being advertised for sale across Github. Recorded Future Triage was used to browse the website advertising the exploit, which can be viewed here via the Replay Monitor. (Source: Recorded Future)
Key Trends: February 2026
Vendors Most Affected
- Microsoft led with six vulnerabilities across Windows, Windows Server, Office, and Microsoft 365 products
- BeyondTrust faced a critical OS command injection flaw in Remote Support (RS) versions 25.3.1 and earlier, and Privileged Remote Access (PRA) versions 24.3.4 and earlier
- Cisco saw active exploitation of an authentication bypass in Catalyst SD-WAN infrastructure
- Additional affected vendors: Notepad++, Apple, Soliton Systems K.K., Google, and Dell
Most Common Weakness Types
- CWE-78 – OS Command Injection (tied for most common)
- CWE-693 – Protection Mechanism Failure (tied for most common)
- CWE-476 – NULL Pointer Dereference
- CWE-843 – Type Confusion
- CWE-807 – Reliance on Untrusted Inputs in a Security Decision
Exploitation Activity
Vulnerabilities associated with malware campaigns:
- Lotus Blossom (suspected China state-sponsored) exploited CVE-2025-15556 to hijack Notepad++ update traffic between June and December 2025. The campaign rotated C2 servers across three attack chains to deliver a Metasploit loader, Cobalt Strike Beacon, and a custom backdoor called Chrysalis.
- APT28 (Russian state-sponsored) exploited CVE-2026-21513 using malicious Windows Shortcut (.lnk) files with embedded HTML payloads for multi-stage payload delivery, with observed network communication to infrastructure associated with the threat group.
- UNC6201 (suspected China-nexus) exploited CVE-2026-22769 to compromise Dell RecoverPoint for VMs appliances, deploying the SLAYSTYLE web shell, BRICKSTORM backdoor, and GRIMBOLT, a C#-based backdoor with native AOT compilation to complicate detection.
Long-running exploitation activity:
- UAT-8616 exploited CVE-2026-20127, chaining it with CVE-2022-20775 to achieve root-level access on Cisco Catalyst SD-WAN systems, with Cisco Talos attributing the activity to a sophisticated threat actor and assessing that the activity dates back to at least 2023.
Priority Alert: Active Exploitation
These vulnerabilities demand immediate attention due to confirmed exploitation in the wild.
CVE-2025-15556 | Notepad++
Risk Score: 99 (Very Critical) | CISA KEV: Added February 12, 2026
Why this matters: Lotus Blossom exploited this flaw to replace legitimate Notepad++ update packages with malicious installers, deploying Cobalt Strike and the Chrysalis backdoor to targeted users over a six-month period. The vulnerability affects the WinGUp updater used by Notepad++ versions prior to 8.8.9, which fails to cryptographically verify downloaded update metadata and installers.
Affected versions: Notepad++ versions prior to 8.8.9 (version 8.9.1 recommended)
Immediate actions:
- Update to Notepad++ version 8.9.1, released January 26, 2026
- Hunt for the malicious update.exe sample (SHA256: 4d4aec6120290e21778c1b14c94aa6ebff3b0816fb6798495dc2eae165db4566) in your environment
- Monitor for GUP.exe spawning unexpected child processes
- Review network connections for traffic to 45[.]76[.]155[.]202, 45[.]77[.]31[.]210, 45[.]32[.]144[.]255, or 95[.]179[.]213[.]0
- Check for directories named ProShow under %APPDATA% or unexpected files in %APPDATA%\Adobe\Scripts\
- Block or alert on curl.exe uploading files to temp[.]sh
Known C2 infrastructure: 45[.]76[.]155[.]202, 45[.]77[.]31[.]210, cdncheck[.]it[.]com, safe-dns[.]it[.]com, 95[.]179[.]213[.]0
Detection resources: Insikt Group created Sigma rules to detect update.exe's execution of reconnaissance commands (whoami, tasklist, systeminfo, and netstat -ano) and curl commands for system information exfiltration, available to Recorded Future customers.
Figure 1: Risk Rules History from Vulnerability Intelligence Card® for CVE-2025-15556 in Recorded Future (Source: Recorded Future)
CVE-2026-1731 | BeyondTrust Remote Support and Privileged Remote Access
Risk Score: 99 (Very Critical) | CISA KEV: Added February 13, 2026
Why this matters: Unauthenticated attackers can execute arbitrary OS commands over a WebSocket connection, enabling remote shell access and full system compromise, with no credentials required.
Affected versions: BeyondTrust Remote Support (RS) versions 25.3.1 and earlier; Privileged Remote Access (PRA) versions 24.3.4 and earlier
Immediate actions:
- Upgrade to BeyondTrust RS version 25.3.2 or later and PRA version 25.1 or later
- Monitor WebSocket connections to the /nw endpoint for crafted version strings containing subshell syntax (e.g.,
a[$(command)]0) - Review logs for unexpected OS command execution originating from wsusservice or web service processes
- Restrict network access to BeyondTrust appliances to authorized management systems only
CVE-2026-20127 | Cisco Catalyst SD-WAN Controller and Manager
Risk Score: 99 (Very Critical) | CISA KEV: Added February 25, 2026
Why this matters: UAT-8616 exploited this authentication bypass to gain high-privileged access to Cisco SD-WAN infrastructure, chaining it with CVE-2022-20775 to achieve root-level access and maintain persistent, covert footholds. CISA issued Emergency Directive 26-03, requiring federal civilian agencies to immediately remediate.
Affected products: Cisco Catalyst SD-WAN Controller (formerly vSmart) and Cisco Catalyst SD-WAN Manager (formerly vManage) in on-premises deployments and SD-WAN Cloud installations
Immediate actions:
- Update to patched release versions 20.9.8.2, 20.12.6.1, 20.12.5.3, 20.15.4.2, or 20.18.2.1
- Monitor SD-WAN logs for unexpected
control-connection-state-change new-state:upevents and unrecognized peer-system-ip values - Audit SSH
authorized_keysfiles at/home/root/.ssh/authorized_keysand/home/vmanage-admin/.ssh/authorized_keys/for unauthorized entries - Check
/etc/ssh/sshd_configforPermitRootLogin yes - Review logs for path traversal strings related to CVE-2022-20775, such as
/../../and/\n&../\n&../ - Hunt for cleared or truncated logs from syslog, wtmp, lastlog, cli-history, bash_history, and files in
/var/log/, which may indicate log clearing
Technical Deep Dive: Exploitation Analysis
Notepad++ Supply-Chain Attack (CVE-2025-15556)
Three-chain attack evolution: Lotus Blossom ran three distinct attack chains between July and October 2025, each evolving to evade detection:
- Chain 1 (July–August 2025): Replaced the legitimate Notepad++ update package with a malicious NSIS installer (update.exe) that abused a legitimate ProShow.exe file to launch an exploit payload containing shellcode. The shellcode decrypted and launched a Metasploit downloader, which retrieved a Cobalt Strike Beacon shellcode from hxxps://45[.]77[.]31[.]210/users/admin and executed it.
- Chain 2 (September 2025): Reused the same update channel with a modified update.exe that dropped legitimate Lua interpreter files alongside a malicious alien.ini script. The compiled Lua script allocated and executed shellcode via the EnumWindowStationsW API, ultimately delivering Cobalt Strike Beacon. Threat actors later split reconnaissance commands into multiple steps to evade detection logic tied to combined command-line patterns.
- Chain 3 (October 2025): Shifted to a new distribution server and delivered a malicious update.exe file that dropped a legitimate Bitdefender Submission Wizard renamed as BluetoothService.exe, a malicious DLL named log.dll, and an encrypted shellcode file. Update.exe executed BluetoothService.exe, which sideloaded log.dll. Log.dll then decrypted the shellcode and injected it into the BluetoothService.exe process.
APT28 MSHTML Exploitation (CVE-2026-21513)
Browser trust boundary abuse: The vulnerability resides in ieframe.dll hyperlink navigation logic, where insufficient URL validation in _AttemptShellExecuteForHlinkNavigate() allows threat actor-controlled input to invoke ShellExecuteExW outside the intended browser security context.
Akamai identified a malicious .lnk file (document.doc.LnK) associated with APT28 infrastructure. The exploit uses nested iframes and multiple DOM contexts to manipulate browser trust boundaries, bypassing both Mark of the Web (MotW) and Internet Explorer Enhanced Security Configuration (IE ESC) before triggering the vulnerable navigation flow. The .lnk initiates network communication with wellnesscaremed[.]com as part of APT28's multistage payload delivery.
SHA256 for document.doc.LnK.download: aefd15e3c395edd16ede7685c6e97ca0350a702ee7c8585274b457166e86b1fa
Why this matters: APT28's use of a weaponized .lnk file exploiting a patched MSHTML flaw underscores the group's continued targeting of Windows environments and its willingness to operationalize browser-based vulnerabilities for initial access.
UNC6201 Dell RecoverPoint Campaign (CVE-2026-22769)
Persistence through VMware infrastructure: UNC6201 exploited hard-coded credentials stored in /home/kos/tomcat9/tomcat-users.xml to authenticate to the Apache Tomcat Manager and upload a malicious WAR file, deploying the SLAYSTYLE web shell and enabling RCE with root privileges.
After establishing access, UNC6201 deployed the BRICKSTORM backdoor for C2, then replaced it with GRIMBOLT in September 2025. GRIMBOLT uses native ahead-of-time (AOT) compilation to convert to machine-native code, removing common intermediate language metadata and complicating static analysis. UNC6201 then pivoted into VMware virtual infrastructure, creating temporary "Ghost NIC" network ports on ESXi-hosted VMs for stealthy lateral movement and implementing Single Packet Authorization (SPA) via iptables commands to gate access to their backdoor infrastructure.
Why this matters: The progression from web shell to persistent backdoors, and then the pivot to VMware infrastructure to support lateral movement demonstrates a mature, multi-stage intrusion methodology. Organizations running Dell RecoverPoint for VMs should assume default credentials have been compromised and hunt for SLAYSTYLE and GRIMBOLT indicators immediately.
Detection Artifacts from Insikt Group®
Recorded Future customers can access the following from Insikt Group®:
- CVE-2025-15556 – Sigma rules to detect reconnaissance commands (whoami, tasklist, systeminfo, netstat -ano) and curl-based exfiltration associated with the Notepad++ supply-chain attack
- CVE-2026-23760 (SmarterTools SmarterMail) – Nuclei template for authentication bypass detection, created in February (previously highlighted in January 2026 CVE Monthly)
Note: All detection artifacts are intended for use in authorized environments only.
Recorded Future Product Integrations
- Vulnerability Intelligence – Prioritize vulnerabilities based on real-world exploitation data, not just severity scores
- Attack Surface Intelligence – Identify exposed BeyondTrust, Cisco SD-WAN, and Dell RecoverPoint assets in your environment
- Third-Party Intelligence – Monitor vendor vulnerability exposure across your supply chain
Take Action
Ready to see how Recorded Future can help your team detect active exploitation, prioritize patching, and reduce attack surface risk? Explore our demo center to see these capabilities in action, or dive deeper into Insikt Group research for more threat intelligence insights.
About Insikt Group®:
Recorded Future's Insikt Group® threat research team is comprised of analysts, linguists, and security researchers with deep government and industry experience. Insikt Group® publishes threat intelligence to the Recorded Future analyst community in blog posts and analyst notes.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.recordedfuture.com/blog/february-2026-cve-landscape