U.S. CISA adds SolarWinds Web Help Desk, Notepad++, Microsoft Configuration Manager, and Apple devices flaws to its Known Exploited Vulnerabilities catalog

3 Min Read

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SolarWinds Web Help Desk, Notepad++, Microsoft Configuration Manager, and Apple devices flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SolarWinds Web Help Desk, Notepad++, Microsoft Configuration Manager, and Apple devices flaws to its Known Exploited Vulnerabilities (KEV) catalog.

- Advertisement -

Below are the flaws added to the catalog:

  • CVE-2024-43468 (CVSS score 9.8) Microsoft Configuration Manager SQL Injection Vulnerability
  • CVE-2025-15556 (CVSS score 7.7) Notepad++ Download of Code Without Integrity Check Vulnerability
  • CVE-2025-40536 (CVSS score 8.1) SolarWinds Web Help Desk Security Control Bypass Vulnerability
  • CVE-2026-20700 (CVSS score 7.8) Apple Multiple Buffer Overflow Vulnerability

The first flaw added to the catalog is a Microsoft Configuration Manager SQL Injection Vulnerability tracked as CVE-2024-43468. An unauthenticated attacker could send specially crafted requests to the system and trigger unsafe processing, allowing them to execute commands on the server or underlying database.


What do you think? Post a comment.


The second flaw added to the catalog is a Notepad++ Download of Code Without Integrity Check tracked as CVE-2025-15556. Vulnerability. Notepad++ versions before 8.8.9 using WinGUp have a flaw where updates aren’t verified. An attacker intercepting update traffic can make the updater run a malicious installer, allowing arbitrary code execution with the user’s privileges.

- Advertisement -

EXPLORE MORE

Battle of Trafalgar: Strategic Necessity or Aggressive Overreach?

CAPE TRAFALGAR — On October 21, 1805, 27 British warships engaged a…

Germany Receives First F-35A as NATO Airpower Grows Amid Rising Threats from Russia

Germany has received its first F-35A stealth fighter from Lockheed Martin as…

Simply Sniffing Dark Chocolate Helped Men Squeeze Out 18 More Reps in the Gym During Leg Day

Credit: Unsplash. Could the smell of chocolate wafting through the gym make…

Senate Blocks Report on Deaths of 9 Americans in the West Bank After Key 47–51 Vote

WASHINGTON, D.C. — In a 47–51 roll-call vote, the United States Senate…

Wanted: Suspects for Commercial Burglary in the 12th District [VIDEO]

The police are investigating a commercial burglary that occurred on February 23,…

The third flaw added to the catalog is a security control bypass vulnerability, tracked as CVE-2025-40536, that could allow an unauthenticated attacker to access certain restricted functionality within Web Help Desk. While more limited in scope than the critical flaws, successful exploitation could still expose sensitive features and weaken the application’s overall security posture.

The last flaw added to the catalog is an Apple Multiple Buffer Overflow Vulnerability tracked as CVE-2026-20700.

This week, Apple released updates for iOS, iPadOS, macOS, watchOS, tvOS, and visionOS to address an actively exploited zero-day tracked as CVE-2026-20700. The flaw is a memory corruption issue in Apple’s Dynamic Link Editor (dyld) that lets attackers execute arbitrary code on vulnerable devices.

Google’s Threat Analysis Group discovered and reported the issue, a circumstance that suggests the flaw may have been exploited by nation-state actors or commercial spyware vendors in attacks in the wild.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by March 5, 2026, except CVE-2025-40536, which must be solved by February 15, 2026.

Pierluigi Paganini



Share This Article

The Iran War Has Turned VLCCs Into $650,000-A-Day Assets

Authored by Julianne Geiger via OilPrice.com, More Gulf oil…

Zionism and the Ottoman Empire: The Final Step to Conquering Palestine

The final step, which lasted until the fall of…

Turkey Recruits Trump Insiders For New Washington Lobbying Push

Via Middle East Eye The Turkish government hired a lobbying firm…

North Korea tests new weapon system (PHOTOS)

DPRK media released photos showing the launch of a…

US-Backed SDF Leader Joins Sharaa Regime As Presidential Advisor After Kurdish Force Dissolved

Via The Cradle Self-proclaimed Syrian President Ahmad al-Sharaa has…

Uprising In Ceuta: Locals Have Had Enough Of Migrant Invasion

Authored by Steve Watson via Modernity News,In the complete…

Kurt Weldon’s 9/11 Bombshell on Jimmy Dore

Former Republican Congressman Kurt Weldon—who served Pennsylvania's 7th district…

CIA Chief's Moscow Trip Was About Iran, Not A NATO Warning: Estonia's Ex-President

Speculation has abounded over the nature of CIA Director John…

CONVERSATION

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted