ZeroHour
Recorded Futurepublished ()ingested Insikt Group®1

January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-1340
+1 in the same advisory: …1281
Unauthenticated Code Injection RCE in Ivanti Endpoint Manager Mobile

CVE-2026-1340 is a code injection flaw (CWE-94) in Ivanti Endpoint Manager Mobile (EPMM), Ivanti's enterprise mobile device management platform, that permits unauthenticated remote code execution. Because the flaw is network-reachable and requires no privileges or user interaction (AV:N/AC:L/PR:N/UI:N), a remote attacker can send a crafted request to a vulnerable EPMM server and execute arbitrary code, with high impact to confidentiality, integrity, and availability. Any organization operating an affected EPMM server is affected, especially those exposing the management or device-enrollment interface to the internet. The flaw was added to CISA's KEV catalog on 2026-04-08 with an 86.2% probability of exploitation within 30 days; news reporting describes active zero-day attacks against EPMM (alongside related CVE-2026-6973), including a confirmed Dutch government incident exposing employee contact data, while ransomware use remains unconfirmed. A large share of observed exploit traffic has been traced to a single IP address on bulletproof hosting infrastructure.

Do: Apply Ivanti's patched EPMM release per the vendor advisory immediately and verify the fix on any internet-facing EPMM portal; US federal agencies must follow BOD 22-01 mitigation deadlines. Until patched, restrict EPMM portal access to trusted networks/VPNs and review access logs for suspicious requests or unrecognized source IPs, noting that much exploit activity has originated from a single bulletproof-hosting IP.

9.886% KEV
  • Ivanti Endpoint Manager Mobile (EPMM)
large≈ tens of thousands of EPMM server deployments, a large share of them internet-exposed
CVE-2026-21509
Local Security Feature Bypass in Microsoft Office Under Active Exploitation

CVE-2026-21509 is a security feature bypass in Microsoft Office caused by reliance on untrusted input when making a security decision (CWE-807): Office trusts attacker-controlled data when deciding whether a protection applies, allowing an unauthorized local attacker to bypass that security feature. Exploitation is local and requires user interaction (per the CVSS vector), most plausibly by getting a user to open a crafted file or document, and the flaw carries high confidentiality, integrity, and availability impact. Anyone running Microsoft Office, Microsoft 365 Apps, or Office Long Term Servicing Channel is in scope, giving the flaw a potential audience in the hundreds of millions of seats. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-26, Microsoft issued an emergency patch, and headlines attribute in-the-wild use to Russian state hackers targeting Ukrainian and EU organizations, including the maritime and transport sectors (a related APT28 campaign was tied to a separate Office/MSHTML 0-day, CVE-2026-21513). EPSS estimates a 72.6% probability of exploitation within the next 30 days (99th percentile).

Do: Apply Microsoft's emergency Office update and the follow-on February 2026 Patch Tuesday fixes across Microsoft 365 Apps, Office, and Office LTSC, checking Microsoft's advisory for the exact affected builds since no version ranges are given in the source data. Given the KEV listing, federal agencies must patch per CISA BOD 22-01 timelines (or follow cloud-service guidance). Hunt for exploitation per vendor guidance — headlines report Russian state use against EU/Ukrainian and maritime/transport targets — and prioritize endpoints where users open untrusted files.

7.873% KEV
  • Microsoft Office
  • Microsoft 365 Apps
  • Microsoft Office Long Term Servicing Channel (LTSC)
masshundreds of millions of users/devices (Office and Microsoft 365 Apps have a global installed base on the order of 10^8+ seats)
CVE-2026-23760
Unauthenticated Admin Password Reset Bypass in SmarterTools SmarterMail

SmarterTools SmarterMail builds prior to 9511 contain an authentication bypass (CWE-288) in the password reset API: the force-reset-password endpoint accepts anonymous requests and, when targeting a system administrator account, never verifies the existing password or requires a reset token. An unauthenticated remote attacker simply submits a target administrator username and a new password, taking over the system administrator account with no privileges or user interaction required. Because SmarterMail's system administrator role can execute operating system commands through built-in management functionality, this escalation effectively yields SYSTEM/root-level access on the underlying mail server host, making it a path to full server and network compromise. All SmarterMail deployments running builds older than 9511 are affected, with roughly 6,000+ likely vulnerable servers observed exposed to the internet. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-26 with known ransomware use (including Storm-1175 and Warlock activity), and public PoCs exist from WatchTowr and Huntress.

Do: Immediately upgrade SmarterMail to build 9511 or later, prioritizing internet-exposed instances. Given known ransomware exploitation and the host-level access this flaw grants, check logs for anonymous calls to the force-reset-password endpoint, unexpected system administrator password changes, and signs of OS command execution or lateral movement on affected hosts. If patching is delayed, restrict or firewall access to the SmarterMail API/web interface, and follow CISA BOD 22-01 guidance for cloud-hosted deployments.

9.396% KEV ransomware PoC ×2
  • SmarterTools SmarterMail All versions prior to build 9511
moderate≈6,000+ internet-exposed SmarterMail servers

Indicators of compromiseAll →

TypeIndicatorContext
domainoutlook.com\Cache\SplashScreen.png Block email addresses: ahmeclaw2002@outlook[.]com and ahmeclaw@proton[.]me CVE-2026-23760 | SmarterTools Sm
domainproton.meck email addresses: ahmeclaw2002@outlook[.]com and ahmeclaw@proton[.]me CVE-2026-23760 | SmarterTools SmarterMail Risk Score: 99
domainwordpress.com26-23800: 62[.]60[.]131[.]161 185[.]102[.]115[.]27 backup[@]wordpress[.]com backup1[@]wordpress[.]com Why this matters: WordPress plu
Full article1,568 words · extracted from recordedfuture.com · click to collapse

January 2026 saw a modest 5% increase in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 23 vulnerabilities requiring immediate remediation, up from 22 in December 2025. Noteworthy trends last month included Russian state-sponsored exploitation of a Microsoft Office zero-day and critical authentication bypass flaws affecting enterprise infrastructure.

What security teams need to know:

  • APT28's Operation Neusploit: Russian state-sponsored actors exploited CVE-2026-21509 (Microsoft Office) via weaponized RTF files, delivering MiniDoor, PixyNetLoader, and Covenant Grunt implants
  • Microsoft and SmarterTools lead concerns: These vendors accounted for 30% of January's vulnerabilities, with multiple critical authentication bypass and RCE flaws
  • Public exploits proliferate: Fourteen of the 23 vulnerabilities reported have public proof-of-concept exploit code available
  • Code Injection dominates: CWE-94 (Code Injection) was the most common weakness type, followed by CWE-288 (Authentication Bypass Using an Alternate Path or Channel) and CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor)

Bottom line: The slight increase masks significant threats. APT28's zero-day exploitation and multiple critical authentication bypass flaws demonstrate that threat actors continue targeting enterprise communication and management platforms for initial access and persistence.

Quick Reference Table

All 23 vulnerabilities below were actively exploited in January 2026.

#

Vulnerability

Risk
Score

Affected Vendor/Product

Vulnerability Type/Component

Public PoC

1

99

Cisco Identity Services Engine Software

CWE-611 (Improper Restriction of XML External Entity Reference)

No

2

99

Microsoft Windows

CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor)

3

99

Microsoft Windows

CWE-73 (External Control of File Name or Path)

No

4

99

Modular DS Plugin

CWE-266 (Incorrect Privilege Assignment)

5

99

GNU InetUtils

CWE-88 (Argument Injection)

6

99

Cisco Unified Communications Manager

CWE-94 (Code Injection)

7

99

SmarterTools SmarterMail

CWE-288 (Authentication Bypass Using an Alternate Path or Channel)

8

99

SmarterTools SmarterMail

CWE-306 (Missing Authentication for Critical Function)

9

99

Microsoft Office

CWE-807 (Reliance on Untrusted Inputs in a Security Decision)

10

99

Fortinet Multiple Products

CWE-288 (Authentication Bypass Using an Alternate Path or Channel)

11

99

SolarWinds Web Help Desk

CWE-502 (Deserialization of Untrusted Data)

No

12

99

Ivanti Endpoint Manager Mobile (EPMM)

CWE-94 (Code Injection)

13

99

Ivanti Endpoint Manager Mobile (EPMM)

CWE-94 (Code Injection)

14

99

Linux Kernel

CWE-190 (Integer Overflow or Wraparound)

15

99

SmarterTools SmarterMail

CWE-434 (Unrestricted Upload of File with Dangerous Type)

16

99

Broadcom VMware vCenter Server

CWE-787 (Out-of-bounds Write)

No

17

99

Synacor Zimbra Collaboration Suite (ZCS)

CWE-98 (PHP Remote File Inclusion)

18

99

Versa Concerto

CWE-288 (Authentication Bypass Using an Alternate Path or Channel)

No

19

99

Vite Vitejs

CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), CWE-284 (Improper Access Control)

20

99

Prettier eslint-config-prettier

CWE-506 (Embedded Malicious Code)

No

21

89

Gogs

CWE-22 (Path Traversal)

22

89

Microsoft Office

CWE-94 (Code Injection)

No

23

89

Hewlett Packard Enterprise OneView

CWE-94 (Code Injection)

Table 1: List of vulnerabilities that were actively exploited in January based on Recorded Future data (Source: Recorded Future)

Key Trends in January 2026

Affected Vendors

  • Microsoft faced four critical vulnerabilities across Windows and Office products, including APT28's zero-day exploitation of CVE-2026-21509
  • SmarterTools accounted for three critical vulnerabilities affecting SmarterMail, all enabling authentication bypass or RCE
  • Cisco saw two critical flaws in Identity Services Engine and Unified Communications Manager
  • Ivanti dealt with two pre-authentication RCE vulnerabilities in Endpoint Manager Mobile
  • Additional affected vendors/projects: Fortinet, SolarWinds, Broadcom, Synacor, Versa, Hewlett Packard Enterprise, GNU, Linux, Vite, Prettier, Gogs, and Modular DS

Most Common Weakness Types

  • CWE-94 – Code Injection
  • CWE-288 – Authentication Bypass Using an Alternate Path or Channel
  • CWE-200 – Exposure of Sensitive Information to an Unauthorized Actor

Threat Actor Activity

APT28's Operation Neusploit marked January's most sophisticated campaign:

  • Exploited CVE-2026-21509 (Microsoft Office) via weaponized RTF files
  • Deployed MiniDoor, a malicious Outlook VBA project designed to collect and forward victim emails to hardcoded addresses
  • Deployed PixyNetLoader, which staged additional components and culminated in a Covenant Grunt implant
  • Abused Filen API as a C2 bridge between the implant and actor-controlled Covenant listener

Priority Alert: Active Exploitation

These vulnerabilities demand immediate attention due to confirmed exploitation in the wild.

CVE-2026-21509 | Microsoft Office

Risk Score: 99 (Very Critical) | Active exploitation by APT28

Why this matters: Zero-day exploitation by Russian state-sponsored actors bypasses Office security features, enabling delivery of email collection implants and backdoors. The vulnerability stems from reliance on untrusted inputs in security decisions, allowing unauthorized attackers to bypass OLE mitigations.

Affected versions: Microsoft 365 and Microsoft Office (versions not specified in advisory)

Immediate actions:

  • Install Microsoft's out-of-band update released January 26, 2026
  • Search email systems for RTF attachments with embedded malicious droppers
  • Check for modifications to %appdata%\Microsoft\Outlook\VbaProject.OTM
  • Review registry keys: HKCU\Software\Microsoft\Office\16.0\Outlook\Security\Level, Software\Microsoft\Office\16.0\Outlook\Options\General\PONT_STRING, and Software\Microsoft\Office\16.0\Outlook\LoadMacroProviderOnBoot
  • Monitor for connections to 213[.]155[.]157[.]123:443 and remote connectivity to Microsoft Office CDN endpoints
  • Hunt for scheduled tasks named "OneDriveHealth" and suspicious files in %programdata%\Microsoft\OneDrive\setup\Cache\SplashScreen.png
  • Block email addresses: ahmeclaw2002@outlook[.]com and ahmeclaw@proton[.]me

CVE-2026-23760 | SmarterTools SmarterMail

Risk Score: 99 (Very Critical) | CISA KEV: Added January 26, 2026

Why this matters: Unauthenticated attackers can reset system administrator passwords without any credentials or prior access, enabling complete administrative takeover and potential RCE through volume mount command injection.

Affected versions: SmarterTools SmarterMail prior to build 9511

Immediate actions:

  • Upgrade to build 9511 or later immediately
  • Review administrator account activity logs for unauthorized password resets
  • Check Volume Mounts configuration for suspicious command entries (this one IS correct for SmarterMail)
  • Review administrator access patterns and session logs
  • Audit system for unauthorized changes made with compromised admin access

CVE-2026-1281 & CVE-2026-1340 | Ivanti Endpoint Manager Mobile

Risk Score: 99 (Very Critical) | CISA KEV: CVE-2026-1281 added January 29, 2026

Why this matters: Pre-authentication RCE vulnerabilities in EPMM enable unauthenticated attackers to execute arbitrary code by exploiting Apache RewriteMap helper scripts that pass attacker-controlled strings to Bash.

Affected versions: Ivanti EPMM 12.5.0.0 and earlier, 12.5.1.0 and earlier, 12.6.0.0 and earlier, 12.6.1.0 and earlier, and 12.7.0.0 and earlier

Immediate actions:

  • Install temporary fixes via RPM packages: EPMM_RPM_12.x.0 - Security Update - 1761642-1.0.0S-5.noarch.rpm and EPMM_RPM_12.x.1 - Security Update - 1761642-1.0.0L-5.noarch.rpm
  • Plan migration to EPMM 12.8.0.0 (scheduled for Q1 2026 release)
  • Monitor for unusual Apache RewriteMap activity
  • Review logs for crafted HTTP parameters to app store retrieval routes
  • Check for unauthorized code execution attempts via RewriteRule handling

Exposure: EPMM instances accessible over corporate networks or VPN connections

Technical Deep Dive: Exploitation Analysis

APT28's Operation Neusploit (CVE-2026-21509)

The multi-stage attack chain: CVE-2026-21509 enables bypass of Office OLE mitigations through weaponized RTF files:

  • Initial delivery Specially-crafted RTF file exploits CVE-2026-21509
  • Server-side evasion Malicious DLL returned only for requests from targeted geographies with an expected HTTP User-Agent
  • Dropper variants Two distinct infection paths deployed based on targeting:
    • Variant 1 (MiniDoor): Writes VBA project to Outlook, modifies registry settings to enable macro execution, forwards emails to hardcoded recipient addresses
    • Variant 2 (PixyNetLoader): Creates mutex asagdugughi41, decrypts embedded payloads using rolling XOR key, establishes persistence via COM hijacking

Why this matters: APT28 demonstrates sophisticated exploitation combining zero-day vulnerabilities with anti-analysis techniques, targeting government and business users for email collection and persistent access.

Modular DS WordPress Plugin Exploitation (CVE-2026-23550 & CVE-2026-23800)

The authentication bypass chain: CVE-2026-23550 enables administrator-level access without authentication:

  • Plugin treats requests as trusted based on request-supplied indicators rather than cryptographic verification
  • /api/modular-connector/login flow grants access based on site connector enrollment state
  • If no user identifier is supplied, the code selects an existing administrative user and establishes a privileged session
  • CVE-2026-23800 represents the second exploitation path via REST API user creation: /?rest_route=/wp/v2/users&origin=mo&type=x

Known IoCs associated with CVE-2026-23550:

  • 45[.]11[.]89[.]19
  • 185[.]196[.]0[.]11
  • 64[.]188[.]91[.]37

Known IoCs associated with CVE-2026-23800:

  • 62[.]60[.]131[.]161
  • 185[.]102[.]115[.]27
  • backup[@]wordpress[.]com
  • backup1[@]wordpress[.]com

Why this matters: WordPress plugin vulnerabilities enable threat actors to compromise multiple sites from a single centralized management platform, amplifying attack impact.

SmarterMail Authentication Bypass (CVE-2026-23760)

The password reset flaw: CVE-2026-23760 exposes privileged password reset to anonymous callers:

  • ForceResetPassword controller attribute explicitly permits unauthenticated access
  • Backend ForcePasswordReset routine branches on client-supplied IsSysAdmin boolean rather than deriving account type from server-side context
  • System administrator branch performs basic checks, then sets Password directly from the supplied NewPassword
  • Logic fails to validate OldPassword, lacks an authenticated session requirement, and omits authorization controls

Why this matters: Complete administrative takeover without credentials enables threat actors to deploy web shells, modify configurations, and establish persistent access to mail server infrastructure.

Nuclei Templates from Insikt Group®

Recorded Future customers can access Nuclei templates for:

  • CVE-2025-8110 (Gogs) - Version detection and fingerprinting check
  • CVE-2026-23760 (SmarterMail) - Authentication bypass validation

Recorded Future Product Integrations

January 2026 Summary

State-sponsored zero-days return. APT28's exploitation of CVE-2026-21509 demonstrates continued Russian interest in email collection and persistent access through Office vulnerabilities.

Authentication bypass dominates enterprise risk. Multiple critical flaws in SmarterMail, Modular DS, and Cisco products enable complete administrative takeover without credentials.

Legacy vulnerabilities persist. CVE-2009-0556 (Microsoft Office) highlights how threat actors continue targeting unretired systems where patching has lagged for over a decade.

Take Action

Ready to see how Recorded Future can help your team detect state-sponsored exploitation, prioritize authentication bypass fixes, and reduce enterprise attack surface? Explore our demo center for live examples, or dive deeper with Insikt Group research for technical threat intelligence.

About Insikt Group®:

Recorded Future's Insikt Group® is a team of elite analysts, linguists, and security researchers providing actionable intelligence to protect organizations worldwide. Our research combines human expertise with AI-powered analytics to deliver timely, relevant threat intelligence on emerging vulnerabilities and threat actor campaigns.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.recordedfuture.com/blog/january-2026-cve-landscape