Multiple Critical CVEs Exploited in Cybersecurity Attacks

Multiple Critical CVEs Exploited in Cybersecurity Attacks

First seen 7 Sep 2026, 18:02 UTC Sploitus 74.6

Article Content

Browse articles
ThreatCluster

A series of vulnerabilities, including CVE-2025-49144, CVE-2025-31702, and CVE-2026-46333, have been identified, affecting systems like Notepad++ and FortiWeb devices. These vulnerabilities allow for local privilege escalation, SQL injection, and remote code execution. Attackers exploit these flaws through various methods, including manipulating installation paths and unauthorized file uploads. The scope of impact includes potentially millions of users and systems that have not yet applied necessary patches. Current reports indicate active exploitation of these vulnerabilities, particularly in the wild. Security professionals are urged to prioritize updates and implement mitigation strategies to protect their systems. Tools and proof-of-concept (PoC) exploits are publicly available, increasing the urgency for remediation.

Key Points: • CVE-2025-49144 allows local privilege escalation in Notepad++ installations. • CVE-2025-31702 enables SQL injection and remote code execution in FortiWeb devices. • Active exploitation of these vulnerabilities has been confirmed, necessitating immediate patching.

Ask AI about this cluster

Timeline

2019-02-11
CVE-2019-5736 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2019-09-25
CVE-2019-16889 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2020-07-01
Public exploit for CVE-2020-15392 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2022-03-03
CVE-2022-22706 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2022-03-16
CVE-2021-39793 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2022-04-13
CVE-2022-24521 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2022-04-15
CVE-2022-24481 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2022-06-27
CVE-2022-31101 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-08-15
CVE-2023-40028 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-03-21
CVE-2025-29927 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE