Weekly Threat Summary
8 vulnerabilities were added to the CISA Known Exploited Vulnerabilities (KEV) catalog this period. The highest CVSS score is 10.0.
This week includes 3 critical-severity vulnerabilities (CVSS 9.0+) that require immediate attention.
This Week's Vulnerabilities
CVE-2026-22769 — Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability
- CVSS Score: 10.0 (CRITICAL)
- Date Added: 2026-02-18
- Description: Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could...
- Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2025-49113 — RoundCube Webmail Deserialization of Untrusted Data Vulnerability
- CVSS Score: 9.9 (CRITICAL)
- Date Added: 2026-02-20
- Description: RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by...
- Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2020-7796 — Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
- CVSS Score: 9.8 (CRITICAL)
- Date Added: 2026-02-17
- Description: Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery vulnerability if WebEx zimlet...
- Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2026-2441 — Google Chromium CSS Use-After-Free Vulnerability
- CVSS Score: 8.8 (HIGH)
- Date Added: 2026-02-17
- Description: Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially...
- Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2008-0015 — Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability
- CVSS Score: 8.8 (HIGH)
- Date Added: 2026-02-17
- Description: Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit...
- Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2024-7694 — TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability
- CVSS Score: 7.2 (HIGH)
- Date Added: 2026-02-17
- Description: TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous type vulnerability....
- Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2025-68461 — RoundCube Webmail Cross-site Scripting Vulnerability
- CVSS Score: 7.2 (HIGH)
- Date Added: 2026-02-20
- Description: RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document.
- Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2021-22175 — GitLab Server-Side Request Forgery (SSRF) Vulnerability
- CVSS Score: 6.8 (MEDIUM)
- Date Added: 2026-02-18
- Description: GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for...
- Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
What This Means for You
If you run any of the affected products, patch immediately. Critical-severity vulnerabilities are actively exploited in the wild — CISA adds them to the KEV catalog specifically because they represent real, current threats.
Use the CVSS Calculator to assess how these scores apply to your specific environment.
Security+ Study Angle
This week's 8 new KEV entries touch multiple attack surfaces — from authentication bypasses to command injection. If you're studying for Security+, this is a live case study in Domain 2: Threats, Vulnerabilities, and Mitigations (22% of the exam).
Map each CVE to a vulnerability type from the SY0-701 objectives. That's how you build real exam intuition.
Tools to Help
- CVSS Calculator — Score these vulnerabilities for your specific environment
- Security+ Practice Quiz — Test your knowledge of vulnerability types and mitigations
Stay Updated
This roundup is published every Tuesday. Bookmark the FixTheVuln Blog to stay on top of the latest threats — or subscribe via RSS.
Explore More
Frequently Asked Questions
What vulnerabilities were reported in the week of 2026-02-28?
8 new CISA KEV vulnerabilities this week. Highest CVSS: 10.0. Review the latest threats added to the Known Exploited Vulnerabilities catalog.
Why should I read weekly threat roundups?
Weekly threat roundups help security professionals stay current with the rapidly evolving threat landscape. They provide condensed analysis of the most critical vulnerabilities, helping teams prioritize patching and allocate defensive resources effectively.
How can I protect my organization from these vulnerabilities?
Regularly review CISA KEV advisories, prioritize patching based on CVSS severity and active exploitation status, and use vulnerability management tools to track your organization's exposure. Our CVSS Calculator and vulnerability guides can help assess risk.
FixTheVuln Store
Studying for Security+? Get the Study Planner
Structured study planners for CompTIA certifications. Domain trackers, time blocking, and exam strategies.
Shop Security+ PlannerAlso available: CompTIA A+, Network+, CySA+, PenTest+
CyberFolio
Building cybersecurity skills? Track them in one place.
Build a shareable cybersecurity portfolio that highlights your certifications, projects, and skills — free.
Build Your Portfolio →