Weekly Threat Summary
11 vulnerabilities were added to the CISA Known Exploited Vulnerabilities (KEV) catalog this period. The highest CVSS score is 10.0.
This week includes 4 critical-severity vulnerabilities (CVSS 9.0+) that require immediate attention.
This Week's Vulnerabilities
CVE-2026-20127 — Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
- CVSS Score: 10.0 (CRITICAL)
- Date Added: 2026-02-25
- Description: Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN...
- Required Action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
CVE-2026-22769 — Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability
- CVSS Score: 10.0 (CRITICAL)
- Date Added: 2026-02-18
- Description: Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could...
- Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2025-49113 — RoundCube Webmail Deserialization of Untrusted Data Vulnerability
- CVSS Score: 9.9 (CRITICAL)
- Date Added: 2026-02-20
- Description: RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by...
- Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2020-7796 — Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
- CVSS Score: 9.8 (CRITICAL)
- Date Added: 2026-02-17
- Description: Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery vulnerability if WebEx zimlet...
- Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2026-25108 — Soliton Systems K.K FileZen OS Command Injection Vulnerability
- CVSS Score: 8.8 (HIGH)
- Date Added: 2026-02-24
- Description: Soliton Systems K.K FileZen contains an OS command injection vulnerability when an user logs-in to the affected...
- Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2026-2441 — Google Chromium CSS Use-After-Free Vulnerability
- CVSS Score: 8.8 (HIGH)
- Date Added: 2026-02-17
- Description: Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially...
- Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2008-0015 — Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability
- CVSS Score: 8.8 (HIGH)
- Date Added: 2026-02-17
- Description: Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit...
- Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2022-20775 — Cisco SD-WAN Path Traversal Vulnerability
- CVSS Score: 7.8 (HIGH)
- Date Added: 2026-02-25
- Description: Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain...
- Required Action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
CVE-2024-7694 — TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability
- CVSS Score: 7.2 (HIGH)
- Date Added: 2026-02-17
- Description: TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous type vulnerability....
- Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2025-68461 — RoundCube Webmail Cross-site Scripting Vulnerability
- CVSS Score: 7.2 (HIGH)
- Date Added: 2026-02-20
- Description: RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document.
- Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2021-22175 — GitLab Server-Side Request Forgery (SSRF) Vulnerability
- CVSS Score: 6.8 (MEDIUM)
- Date Added: 2026-02-18
- Description: GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for...
- Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
What This Means for You
If you run any of the affected products, patch immediately. Critical-severity vulnerabilities are actively exploited in the wild — CISA adds them to the KEV catalog specifically because they represent real, current threats.
Use the CVSS Calculator to assess how these scores apply to your specific environment.
Cert Study Angles
These CVEs map directly to certification exam objectives. Use them as real-world case studies:
CompTIA Security+
- CVE-2026-20127 → D2 Threats & Vulnerabilities
- CVE-2025-49113 → D2 Threats & Vulnerabilities
- CVE-2026-25108 → D2 Threats & Vulnerabilities, D4 Security Operations
- CVE-2008-0015 → D2 Threats & Vulnerabilities
- CVE-2024-7694 → D2 Threats & Vulnerabilities
- CVE-2025-68461 → D2 Threats & Vulnerabilities
ISC2 CISSP
- CVE-2026-20127 → D5 IAM, D6 Security Assessment
- CVE-2026-22769 → D6 Security Assessment
- CVE-2025-49113 → D6 Security Assessment
- CVE-2020-7796 → D6 Security Assessment
- CVE-2026-25108 → D6 Security Assessment
- CVE-2026-2441 → D6 Security Assessment
- CVE-2008-0015 → D6 Security Assessment
- CVE-2022-20775 → D6 Security Assessment
- CVE-2024-7694 → D6 Security Assessment
- CVE-2025-68461 → D6 Security Assessment
- CVE-2021-22175 → D4 Communication & Network, D6 Security Assessment
Cisco CCNA
- CVE-2025-68461 → D1 Network Fundamentals
See all CVEs mapped to your cert: Exploit Tracker
Tools to Help
- CVSS Calculator — Score these vulnerabilities for your specific environment
- Exploit Tracker — Filter KEV vulnerabilities by certification relevance
- Study Tracker — Track your exam objective completion
- Security+ Practice Quiz — Test your knowledge of vulnerability types and mitigations
Stay Updated
This roundup is published every Tuesday. Bookmark the FixTheVuln Blog to stay on top of the latest threats — or subscribe via RSS.
Explore More
Frequently Asked Questions
What vulnerabilities were reported in the week of 2026-03-03?
11 new CISA KEV vulnerabilities this week. Highest CVSS: 10.0. Review the latest threats added to the Known Exploited Vulnerabilities catalog.
Why should I read weekly threat roundups?
Weekly threat roundups help security professionals stay current with the rapidly evolving threat landscape. They provide condensed analysis of the most critical vulnerabilities, helping teams prioritize patching and allocate defensive resources effectively.
How can I protect my organization from these vulnerabilities?
Regularly review CISA KEV advisories, prioritize patching based on CVSS severity and active exploitation status, and use vulnerability management tools to track your organization's exposure. Our CVSS Calculator and vulnerability guides can help assess risk.
FixTheVuln Store
CISSP Exam Prep? Get the Study Planner
Comprehensive planner for (ISC)2 certifications. Domain-mapped study schedules, practice tracking, and more.
Shop CISSP PlannerAlso available: SSCP, CCSP
CyberFolio
Building cybersecurity skills? Track them in one place.
Build a shareable cybersecurity portfolio that highlights your certifications, projects, and skills — free.
Build Your Portfolio →