CISA's list that day

12 February 2026

On CISA added 4 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Configuration Manager, Notepad++, SolarWinds Web Help Desk and 1 other product. The US federal deadlines run from to .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-40536Security Control BypassSolarWinds Web Help DeskPatch this weekMetasploit module; EPSS 0.740.74
CVE-2024-43468SQL InjectionMicrosoft Configuration ManagerPatch this weekEPSS 0.810.81
CVE-2025-15556Download of Code Without Integrity CheckNotepad++ Notepad++Patch soon0.02
CVE-2026-20700Multiple Buffer OverflowApple Multiple ProductsPatch soon0.01