Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

CISA Warns of Exploited SolarWinds, Notepad++, Microsoft Vulnerabilities

Disclosed at the end of January, the SolarWinds vulnerability was likely exploited as a zero-day since December 2025.

CISA KEV

The US cybersecurity agency CISA on Thursday warned that recently disclosed SolarWinds, Notepad++, and Apple vulnerabilities have been exploited in the wild.

Tracked as CVE-2025-40536 (CVSS score of 8.1) and disclosed at the end of January, the SolarWinds flaw is described as a security control bypass in Web Help Desk (WHD) that could allow unauthenticated attackers to access restricted functionality.

The security defect was found and reported by Horizon3.ai, which warned that it could be exploited to create a valid AjaxProxy instance, allowing attackers to exploit additional bugs to achieve remote code execution (RCE).

On Thursday, CISA added CVE-2025-40536 to its Known Exploited Vulnerabilities (KEV) list, urging federal agencies to patch it within three days.

The agency has not shared details on the observed exploitation, but its warning comes a week after Microsoft said that CVE-2025-40536 might have been exploited as a zero-day in an attack observed in December 2025.

The tech giant said that CVE-2025-40551, another fresh WHD issue that was added to CISA’s KEV list last week, might have been targeted as a zero-day as well, in the same attack.

Advertisement. Scroll to continue reading.

Another zero-day added to CISA’s KEV list on Thursday is CVE-2026-20700, a buffer overflow vulnerability that Apple has just patched, warning it has been exploited in an extremely sophisticated attack.

Another newly disclosed vulnerability that has made it to CISA’s KEV list is CVE-2025-15556, an update integrity verification flaw in Notepad++ patched in early February.

Rooted in the lack of cryptographic verification of downloaded update metadata and installers, the issue affects Notepad++ deployments using the WinGUp updater and could allow attackers to intercept update traffic and supply modified installers, achieving arbitrary code execution.

China-linked hackers were seen exploiting the flaw for initial access in attacks that likely started in June 2025. Rapid7 has attributed the campaign to the cyberespionage group tracked as Lotus Blossom.

The fourth CVE added to CISA’s KEV list on Thursday is CVE-2024-43468, a critical-severity RCE flaw in Microsoft Configuration Manager that was resolved in October 2024

It is described as an SQL injection bug that can be exploited without authentication or user interaction via specially crafted requests. 

Proof-of-concept (PoC) code targeting CVE-2024-43468 has been publicly available for over a year, but there appear to have been no reports of it being exploited in attacks prior to CISA’s warning.

CISA has given federal agencies three weeks to apply patches for the Apple, Microsoft, and Notepad++ vulnerabilities.

Related: Chrome 145 Patches 11 Vulnerabilities

Related: Chipmaker Patch Tuesday: Over 80 Vulnerabilities Addressed by Intel and AMD

Related: 6 Actively Exploited Zero-Days Patched by Microsoft With February 2026 Updates

Related: Critical SmarterMail Vulnerability Exploited in Ransomware Attacks

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Tracey Mustacchio has joined Everfox as Chief Marketing Officer.

Mark Carter has been appointed Chief Information Security Officer at Socure.

Spektrum Labs has named Mark Cravotta Chief Operating Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.