U.S. CISA adds SolarWinds Web Help Desk, Notepad++, Microsoft Configuration Manager, and Apple devices flaws to its Known Exploited Vulnerabilities catalog

3 Min Read

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SolarWinds Web Help Desk, Notepad++, Microsoft Configuration Manager, and Apple devices flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SolarWinds Web Help Desk, Notepad++, Microsoft Configuration Manager, and Apple devices flaws to its Known Exploited Vulnerabilities (KEV) catalog.

- Advertisement -

Below are the flaws added to the catalog:

  • CVE-2024-43468 (CVSS score 9.8) Microsoft Configuration Manager SQL Injection Vulnerability
  • CVE-2025-15556 (CVSS score 7.7) Notepad++ Download of Code Without Integrity Check Vulnerability
  • CVE-2025-40536 (CVSS score 8.1) SolarWinds Web Help Desk Security Control Bypass Vulnerability
  • CVE-2026-20700 (CVSS score 7.8) Apple Multiple Buffer Overflow Vulnerability

The first flaw added to the catalog is a Microsoft Configuration Manager SQL Injection Vulnerability tracked as CVE-2024-43468. An unauthenticated attacker could send specially crafted requests to the system and trigger unsafe processing, allowing them to execute commands on the server or underlying database.


What do you think? Post a comment.


The second flaw added to the catalog is a Notepad++ Download of Code Without Integrity Check tracked as CVE-2025-15556. Vulnerability. Notepad++ versions before 8.8.9 using WinGUp have a flaw where updates aren’t verified. An attacker intercepting update traffic can make the updater run a malicious installer, allowing arbitrary code execution with the user’s privileges.

- Advertisement -

EXPLORE MORE

Architect of Empire, Harbinger of Famine: The Legacy of Sir Charles Trevelyan

Sir Charles Edward Trevelyan, 1st Baronet (1807–1886) stands as one of the…

Earth’s Core Could Be Hiding the Equivalent of up to 45 Oceans of Water

The Earth’s core might not be what we once thought. Credit: Argonne…

Wage Gains for Bottom 25% of Working Americans Are Up 5.5% – Every Week We See Real Wage Gains”

Treasury Secretary Scott Bessent was on Newsmax‘s “Rob Schmitt Tonight” on Friday…

Couple receives custody of baby they wanted surrogate to abort

In a stunning turn of events, the “commissioning” parents who demanded that…

Why Russia Issued an Arrest Warrant for a Gay British Agitator

Caolan Robertson is an British YouTube video maker, amateur writer, and a…

Is Callsign: Sky Shaker the Next Ace Combat?

Big AAA studios are restructuring, but the solo developer behind Callsign: Sky…

The third flaw added to the catalog is a security control bypass vulnerability, tracked as CVE-2025-40536, that could allow an unauthenticated attacker to access certain restricted functionality within Web Help Desk. While more limited in scope than the critical flaws, successful exploitation could still expose sensitive features and weaken the application’s overall security posture.

The last flaw added to the catalog is an Apple Multiple Buffer Overflow Vulnerability tracked as CVE-2026-20700.

This week, Apple released updates for iOS, iPadOS, macOS, watchOS, tvOS, and visionOS to address an actively exploited zero-day tracked as CVE-2026-20700. The flaw is a memory corruption issue in Apple’s Dynamic Link Editor (dyld) that lets attackers execute arbitrary code on vulnerable devices.

Google’s Threat Analysis Group discovered and reported the issue, a circumstance that suggests the flaw may have been exploited by nation-state actors or commercial spyware vendors in attacks in the wild.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by March 5, 2026, except CVE-2025-40536, which must be solved by February 15, 2026.

Pierluigi Paganini



Share This Article

From Competitive Ballroom to Digital Stardom: The Evolution of Emily Dobson

Emily Dobson has emerged as one of Generation Z’s…

Kurt Weldon’s 9/11 Bombshell on Jimmy Dore

Former Republican Congressman Kurt Weldon—who served Pennsylvania's 7th district…

Inside Abby Hornacek’s World: The FOX Nation Host on Adventure, Family, and Chasing Her Passions

Whether she’s sandboarding down massive dunes, touring iconic sports…

The Songwriter Who Taught America How to Love: Remembering Dolly Parton

There are rare figures in American culture who do…

Key Democratic Senate Candidate’s Campaign Descends Into ‘Complete Chaos’

Just hours before a key jungle primary decided the…

Resurfaced Childhood Photo of Hasan Piker Triggers Online Debate Over Wealth and Authenticity

An old photograph of political commentator and Twitch streamer…

Iran's Ghalibaf Declares Persian Gulf Oil Flows For 'All Or None'

Via The CradleIranian Parliament Speaker Mohammad Bagher Ghalibaf declared…

CONVERSATION

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted