Weekly Threat Summary
6 vulnerabilities were added to the CISA Known Exploited Vulnerabilities (KEV) catalog this period. The highest CVSS score is 9.8.
This week includes 4 critical-severity vulnerabilities (CVSS 9.0+) that require immediate attention.
This Week's Vulnerabilities
CVE-2025-40551 — SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
- CVSS Score: 9.8 (CRITICAL)
- Date Added: 2026-02-03
- Description: SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code...
- Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2019-19006 — Sangoma FreePBX Improper Authentication Vulnerability
- CVSS Score: 9.8 (CRITICAL)
- Date Added: 2026-02-03
- Description: Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to...
- Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2026-1281 — Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
- CVSS Score: 9.8 (CRITICAL)
- Date Added: 2026-01-29
- Description: Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve...
- Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2026-24858 — Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
- CVSS Score: 9.8 (CRITICAL)
- Date Added: 2026-01-27
- Description: Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate...
- Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2025-64328 — Sangoma FreePBX OS Command Injection Vulnerability
- CVSS Score: 8.6 (HIGH)
- Date Added: 2026-02-03
- Description: Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a...
- Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2021-39935 — GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability
- CVSS Score: 6.8 (MEDIUM)
- Date Added: 2026-02-03
- Description: GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow...
- Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
What This Means for You
If you run any of the affected products, patch immediately. Critical-severity vulnerabilities are actively exploited in the wild — CISA adds them to the KEV catalog specifically because they represent real, current threats.
Use the CVSS Calculator to assess how these scores apply to your specific environment.
Security+ Study Angle
This week's 6 new KEV entries touch multiple attack surfaces — from authentication bypasses to command injection. If you're studying for Security+, this is a live case study in Domain 2: Threats, Vulnerabilities, and Mitigations (22% of the exam).
Map each CVE to a vulnerability type from the SY0-701 objectives. That's how you build real exam intuition.
Tools to Help
- CVSS Calculator — Score these vulnerabilities for your specific environment
- Security+ Practice Quiz — Test your knowledge of vulnerability types and mitigations
Stay Updated
This roundup is published every Tuesday. Bookmark the FixTheVuln Blog to stay on top of the latest threats — or subscribe via RSS.
Explore More
Frequently Asked Questions
What vulnerabilities were reported in the week of 2026-02-20?
6 new CISA KEV vulnerabilities this week. Highest CVSS: 9.8. Review the latest threats added to the Known Exploited Vulnerabilities catalog.
Why should I read weekly threat roundups?
Weekly threat roundups help security professionals stay current with the rapidly evolving threat landscape. They provide condensed analysis of the most critical vulnerabilities, helping teams prioritize patching and allocate defensive resources effectively.
How can I protect my organization from these vulnerabilities?
Regularly review CISA KEV advisories, prioritize patching based on CVSS severity and active exploitation status, and use vulnerability management tools to track your organization's exposure. Our CVSS Calculator and vulnerability guides can help assess risk.
FixTheVuln Store
Studying for Security+? Get the Study Planner
Structured study planners for CompTIA certifications. Domain trackers, time blocking, and exam strategies.
Shop Security+ PlannerAlso available: CompTIA A+, Network+, CySA+, PenTest+
CyberFolio
Building cybersecurity skills? Track them in one place.
Build a shareable cybersecurity portfolio that highlights your certifications, projects, and skills — free.
Build Your Portfolio →