This Week in Threats: Feb 06–Feb 20, 2026

Expert cybersecurity insights for IT professionals

Last updated: February 21, 2026

By FixTheVuln Team Peer-reviewed security content Sources: CISA Known Exploited Vulnerabilities Catalog, NVD

Weekly Threat Summary

6 vulnerabilities were added to the CISA Known Exploited Vulnerabilities (KEV) catalog this period. The highest CVSS score is 9.8.

This week includes 4 critical-severity vulnerabilities (CVSS 9.0+) that require immediate attention.

This Week's Vulnerabilities

CVE-2025-40551 — SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

CVE-2019-19006 — Sangoma FreePBX Improper Authentication Vulnerability

CVE-2026-1281 — Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

CVE-2026-24858 — Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability

CVE-2025-64328 — Sangoma FreePBX OS Command Injection Vulnerability

CVE-2021-39935 — GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability

What This Means for You

If you run any of the affected products, patch immediately. Critical-severity vulnerabilities are actively exploited in the wild — CISA adds them to the KEV catalog specifically because they represent real, current threats.

Use the CVSS Calculator to assess how these scores apply to your specific environment.

Security+ Study Angle

This week's 6 new KEV entries touch multiple attack surfaces — from authentication bypasses to command injection. If you're studying for Security+, this is a live case study in Domain 2: Threats, Vulnerabilities, and Mitigations (22% of the exam).

Map each CVE to a vulnerability type from the SY0-701 objectives. That's how you build real exam intuition.

Tools to Help

Stay Updated

This roundup is published every Tuesday. Bookmark the FixTheVuln Blog to stay on top of the latest threats — or subscribe via RSS.

Explore More

Free Security Tools Practice Quizzes Cert Comparisons

Frequently Asked Questions

What vulnerabilities were reported in the week of 2026-02-20?

6 new CISA KEV vulnerabilities this week. Highest CVSS: 9.8. Review the latest threats added to the Known Exploited Vulnerabilities catalog.

Why should I read weekly threat roundups?

Weekly threat roundups help security professionals stay current with the rapidly evolving threat landscape. They provide condensed analysis of the most critical vulnerabilities, helping teams prioritize patching and allocate defensive resources effectively.

How can I protect my organization from these vulnerabilities?

Regularly review CISA KEV advisories, prioritize patching based on CVSS severity and active exploitation status, and use vulnerability management tools to track your organization's exposure. Our CVSS Calculator and vulnerability guides can help assess risk.

FixTheVuln Store

Studying for Security+? Get the Study Planner

Structured study planners for CompTIA certifications. Domain trackers, time blocking, and exam strategies.

Shop Security+ Planner

Also available: CompTIA A+, Network+, CySA+, PenTest+

CyberFolio

Building cybersecurity skills? Track them in one place.

Build a shareable cybersecurity portfolio that highlights your certifications, projects, and skills — free.

Build Your Portfolio →
← Back to Home ← All Blog Posts