U.S. CISA adds Google Chromium CSS, Microsoft Windows, TeamT5 ThreatSonar Anti-Ransomware, and Zimbra flaws to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2008-0015 | Remote Code Execution in Microsoft Windows Video ActiveX Control CVE-2008-0015 is a remote code execution vulnerability in the Microsoft Windows Video ActiveX Control, a browser-hostable component bundled with Windows. It is triggered when a user views a specially crafted web page that instantiates the vulnerable control, which lets the attacker's code run in the context of the logged-on user. A successful attacker gains the same user rights as the victim, so an administrator browsing with elevated rights would face full system compromise; any Windows user who views web content with the control enabled is affected. Per CISA the flaw is being actively exploited (added to the Known Exploited Vulnerabilities catalog on 2026-02-17, ransomware use unknown), and EPSS assigns it a 76.7% probability of exploitation within 30 days, placing it in the top percentile. Do: Apply Microsoft's security update for the Windows Video ActiveX Control; as interim mitigation, apply the vendor-documented kill-bit registry keys (including the out-of-band 'Isolated' kill bit Microsoft shipped) so the control cannot be instantiated in Internet Explorer. Because the flaw is on the CISA KEV list, federal agencies must remediate within BOD 22-01 timelines (or apply vendor mitigations for cloud services), and defenders should audit legacy Windows hosts for use of this control, discourage browsing with administrator rights, and prioritize patching systems used for web browsing. | — | 77% | KEV |
| massmass-scale: the vulnerable ActiveX control shipped by default across the Windows installed base (on the order of hundreds of millions of endpoints… | |
| CVE-2020-7796 | Unauthenticated SSRF in Synacor Zimbra Collaboration Suite (CVE-2020-7796) CVE-2020-7796 is a server-side request forgery (SSRF, CWE-918) in Synacor Zimbra Collaboration Suite (ZCS) versions before 8.8.15 Patch 7, rated critical at CVSS 9.8 with network reachability and no authentication or privileges required. The flaw is triggered when the WebEx zimlet is installed and zimlet JSP processing is enabled, allowing an unauthenticated remote attacker to make the Zimbra server issue attacker-controlled requests. Successful SSRF can let the attacker reach internal network services from the mail server's position (e.g., internal admin interfaces or other hosts behind the firewall), potentially leading to information disclosure or further compromise, and the CVSS vector indicates high impact to confidentiality, integrity, and availability. Any organization running a vulnerable Zimbra version with the WebEx zimlet present is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-17, confirming active exploitation, and it carries a very high EPSS score (84.4%, top percentile) amid a reported coordinated surge in SSRF exploitation activity. Do: Upgrade Zimbra Collaboration Suite to 8.8.15 Patch 7 or later. If patching must be delayed, remove or disable the WebEx zimlet and disable zimlet JSP processing to eliminate the trigger; first check whether the WebEx zimlet is installed, since instances without it are not exposed to this specific flaw. As a KEV entry, federal agencies must apply vendor mitigations per BOD 22-01 (or discontinue use if unavailable), and all operators should review Zimbra logs for unauthenticated requests reaching zimlet JSP endpoints. | 9.8 | 84% | KEV |
| largetens of thousands of internet-exposed Zimbra servers (public internet scans); the exploitable subset with the WebEx zimlet installed is smaller and of unknown… | |
| CVE-2024-7694 | Unrestricted File Upload RCE in TeamT5 ThreatSonar Anti-Ransomware TeamT5 ThreatSonar Anti-Ransomware fails to properly validate the content of uploaded files, allowing unrestricted upload of dangerous file types (CWE-434). The flaw is triggered by a remote attacker who already holds administrator privileges on the ThreatSonar platform; after authenticating as an admin, the attacker uploads a malicious file that is used to execute arbitrary system commands on the underlying server. Successful exploitation results in full compromise of the host running the product, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 7.2). All deployments of TeamT5 ThreatSonar Anti-Ransomware are affected per CISA; the available data does not specify affected or fixed version ranges. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2026-02-17 following evidence of active exploitation, though no public proof-of-concept is known and ransomware use is unconfirmed. Do: Apply mitigations per TeamT5's vendor instructions, following CISA BOD 22-01 timelines for federal agencies, or discontinue use of the product if mitigations are unavailable. Restrict and audit administrator accounts on the ThreatSonar platform, review upload activity and system logs for unexpected commands or processes on the host, and verify current mitigation guidance against the latest TeamT5 advisory since specific fixed versions are not listed in this data. | 7.2 | 2% | KEV |
| nichelikely no more than a few thousand deployments, concentrated in Taiwan (estimate; no public install counts) | |
| CVE-2026-2441 | Use-After-Free in Google Chromium CSS Rendering Exposes Chrome, Edge, Opera Users CVE-2026-2441 is a use-after-free (CWE-416) in Google Chromium's CSS handling that a remote attacker can trigger by getting a user's browser to process a crafted HTML page, potentially corrupting the heap. Successful exploitation yields a memory-corruption primitive in the browser; CVSS scoring is not yet available, but Chromium memory-safety flaws of this class can range from crashes to potential code execution depending on how the corruption is leveraged. Anyone running Chromium or a Chromium-based browser — Google Chrome, Microsoft Edge, Opera, and numerous embedded/branded browsers — is potentially affected, making the exposed population effectively all modern browser users. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-02-17, confirming it is being exploited in the wild; EPSS assigns a 22% probability of exploitation within 30 days (98th percentile), no public PoC is known, and any ransomware association is unknown. This lands amid an accelerating series of actively exploited Chrome zero-days in 2026 described in recent reporting, making rapid patching urgent. Do: Update Chromium and every Chromium-based browser in your estate (Chrome, Edge, Opera, Brave, and embedded browsers) to the latest vendor-stable release — recent reporting places the current patched release at Chrome 153 — and verify installed versions via the browser's About/Settings page. Per CISA's KEV required action, apply mitigations per vendor instructions or follow BOD 22-01 guidance for cloud services, and discontinue use if mitigations are unavailable. Until patched, restrict high-risk users' browsing to trusted sites and monitor vendor advisories for the specific fixed build, since exact version details are not yet published in this data. | 8.8 | 22% | KEV PoC |
| massbillions of users (Chromium underpins Chrome alone at ~3B+ users, plus Edge, Opera, and dozens of embedded browsers) |
Full article613 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
February 18, 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium CSS, Microsoft Windows, TeamT5 ThreatSonar Anti-Ransomware, and Zimbra flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Google Chromium CSS, Microsoft Windows, TeamT5 ThreatSonar Anti-Ransomware, and Zimbra flaws to its Known Exploited Vulnerabilities (KEV) catalog.
Below are the flaws added to the catalog:
- CVE-2008-0015 (CVSS score of 8.8) Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability
- CVE-2020-7796 (CVSS score of 9.8) Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
- CVE-2024-7694 (CVSS score of 7.2) TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability
- CVE-2026-2441 (CVSS score of 8.8) Google Chromium CSS Use-After-Free Vulnerability
The first flaw added to the catalog is CVE-2026-2441, which is a Use after free in CSS component in Google Chrome prior to 145.0.7632.75. This week, Google released urgent security updates to address this high-severity zero-day vulnerability. This is the first actively exploited Chrome zero-day fixed in 2026, after eight similar flaws were patched in 2025.
An attacker could exploit the flaw to compromise affected systems. The issue was discovered and responsibly reported by security researcher Shaheen Fazim on February 11, 2026.
“CVE-2026-2441: Use after free in CSS. Reported by Shaheen Fazim on 2026-02-11.” reads the Google’s advisory. “Google is aware that an exploit for CVE-2026-2441 exists in the wild.”
Google has confirmed that an exploit for CVE-2026-2441 exists in the wild, but has not shared details about how it is being used or which threat actor is behind the exploitation of the flaw.
The second flaw, tracked as CVE-2024-7694, impacts TeamT5 ThreatSonar Anti-Ransomware. The issue is an arbitrary file upload vulnerability due to improper validation of uploaded content. An authenticated attacker with administrator privileges can upload crafted malicious files to the platform. This may allow arbitrary system command execution on the server, potentially leading to full system compromise, data exposure, and disruption of security functions.
The third flaw added to the catalog, tracked as CVE-2020-7796, impacts Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7. The issue is an SSRF that can be exploited if the WebEx Zimlet is installed and its JSP component is enabled. An attacker can trick the server into making unauthorized outbound requests, potentially accessing internal services or sensitive resources. In March 2025, Threat intelligence firm GreyNoise observed Grafana path traversal exploitation attempts before the Server-Side Request Forgery (SSRF) surge on March 9, suggesting that attackers may be leveraging Grafana as an initial entry point for deeper exploitation. One of the vulnerabilities exploited in the attacks observed by the experts is CVE-2020-7796. Most Server-Side Request Forgery exploitation attempts targeted entities in the United States, Germany, Singapore, India, Lithuania, Japan, and Israel.
The experts warned that attackers leverage SSRF for pivoting and reconnaissance and cloud exploitation.
The last flaw added to the catalog, tracked as CVE-2008-0015, is a stack-based buffer overflow in the in CComVariant::ReadFromStream within ATL, used by the MPEG2TuneRequest ActiveX control (msvidctl.dll) in DirectShow, affects multiple legacy Windows versions. A crafted web page can trigger remote code execution. The flaw was exploited in the wild in July 2009.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the vulnerabilities by March 10, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/188163/uncategorized/u-s-cisa-adds-google-chromium-css-microsoft-windows-teamt5-threatsonar-anti-ransomware-and-zimbra-flaws-to-its-known-exploited-vulnerabilities-catalog.html