By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: CISA Flags Four Security Flaws Under Active Exploitation in Latest KEV Update
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > CISA Flags Four Security Flaws Under Active Exploitation in Latest KEV Update
Computing

CISA Flags Four Security Flaws Under Active Exploitation in Latest KEV Update

News Room
Last updated: 2026/02/18 at 2:43 AM
News Room Published 18 February 2026
Share
CISA Flags Four Security Flaws Under Active Exploitation in Latest KEV Update
SHARE

Ravie LakshmananFeb 18, 2026Threat Intelligence / Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.

The list of vulnerabilities is as follows –

  • CVE-2026-2441 (CVSS score: 8.8) – A use-after-free vulnerability in Google Chrome that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page.
  • CVE-2024-7694 (CVSS score: 7.2) – An arbitrary file upload vulnerability in TeamT5 ThreatSonar Anti-Ransomware versions 3.4.5 and earlier that could allow an attacker to upload malicious files and achieve arbitrary system command execution on the server.
  • CVE-2020-7796 (CVSS score: 9.8) – A server-side request forgery (SSRF) vulnerability in Synacor Zimbra Collaboration Suite (ZCS) that could allow an attacker to send a crafted HTTP request to a remote host and obtain unauthorized access to sensitive information.
  • CVE-2008-0015 (CVSS score: 8.8) – A stack-based buffer overflow vulnerability in Microsoft Windows Video ActiveX Control that could allow an attacker to achieve remote code execution by setting up a specially crafted web page.

The addition of CVE-2026-2441 to the KEV catalog comes days after Google acknowledged that “an exploit for CVE-2026-2441 exists in the wild.” It’s currently not known how the vulnerability is being weaponized, but such information is typically withheld until a majority of the users are updated with a fix so as to prevent other threat actors from joining the exploitation bandwagon.

As for CVE-2020-7796, a report published by threat intelligence firm GreyNoise in March 2025 revealed that a cluster of about 400 IP addresses was actively exploiting multiple SSRF vulnerabilities, including CVE-2020-7796, to target susceptible instances in the U.S., Germany, Singapore, India, Lithuania, and Japan.

“When a user visits a web page containing an exploit detected as Exploit:JS/CVE-2008-0015, it may connect to a remote server and download other malware,” Microsoft notes in its threat encyclopedia. It also said it’s aware of cases where the exploit is used to download and execute Dogkild, a worm that propagates via removable drives.

The worm comes with capabilities to retrieve and run additional binaries, overwrite certain system files, terminate a long list of security-related processes, and even replace the Windows Hosts file in an attempt to prevent users from accessing websites associated with security programs.

It’s presently unclear how the TeamT5 ThreatSonar Anti-Ransomware vulnerability is being exploited. Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary fixes by March 10, 2026, for optimal protection.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article China Loves The Newest iPhone Model For A Very Colorful Reason – BGR China Loves The Newest iPhone Model For A Very Colorful Reason – BGR
Next Article Apple is developing AI smart glasses, AirPods, and pendant, report says Apple is developing AI smart glasses, AirPods, and pendant, report says
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Today's NYT Wordle Hints, Answer and Help for Feb. 18 #1705 – CNET
Today's NYT Wordle Hints, Answer and Help for Feb. 18 #1705 – CNET
News
U.S. court bars OpenAI from using ‘Cameo’ |  News
U.S. court bars OpenAI from using ‘Cameo’ | News
News
FreeBSD’s KDE Desktop Install Option Ready For Testing
FreeBSD’s KDE Desktop Install Option Ready For Testing
Computing
Fyld eyes US expansion as AI worksite safety group raises £32m – UKTN
Fyld eyes US expansion as AI worksite safety group raises £32m – UKTN
News

You Might also Like

FreeBSD’s KDE Desktop Install Option Ready For Testing
Computing

FreeBSD’s KDE Desktop Install Option Ready For Testing

2 Min Read
KTransformers enables DeepSeek-R1 with low-cost graphics card · TechNode
Computing

KTransformers enables DeepSeek-R1 with low-cost graphics card · TechNode

4 Min Read
Gen Alpha Trends & Characteristics: What Brands Need to Know
Computing

Gen Alpha Trends & Characteristics: What Brands Need to Know

2 Min Read
Centrifuge & Pharos Partner to Advance Onchain Distribution as Tokenized RWAs Cross  Billion | HackerNoon
Computing

Centrifuge & Pharos Partner to Advance Onchain Distribution as Tokenized RWAs Cross $36 Billion | HackerNoon

7 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?