Related Threat Clusters
-
Critical Vulnerabilities in Microsoft SCCM Enable Remote Code Execution for $58
Security researchers from XM Cyber have identified a chain of vulnerabilities in Microsoft System Center Configuration Manager (SCCM) that allows standard domain users to achieve remote code execution. The attack…
8 articles · Updated August 13, 2026 -
CISA Issues Warning on SQL Injection Vulnerability in Microsoft Configuration Manager
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a critical SQL injection vulnerability in Microsoft Configuration Manager that is currently being actively exploited.…
8 articles · Updated February 13, 2026 -
CISA Adds New Vulnerabilities to Known Exploited Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including flaws in SolarWinds Web Help Desk, Notepad++,…
95 articles · Updated February 13, 2026 -
Microsoft Patches CVE-2026-21525 Affecting Windows VPN Services
Microsoft has released a patch for CVE-2026-21525, a vulnerability in the RasMan component that can crash Windows VPN services and disrupt remote access. This flaw has been actively exploited, prompting its addition to…
3 articles · Updated February 11, 2026 -
Multiple Vulnerabilities in Microsoft Products Identified
A series of vulnerabilities, collectively identified as CVE-2025, have been reported across various Microsoft products, including Windows, Microsoft Office, and SQL Server. These vulnerabilities allow authorized and…
55 articles · Updated November 11, 2025 -
Windows 10 ESU Activation Requirements and Updates
Windows 10 support ended on October 14, 2025, but organizations can still receive critical updates through the Extended Security Updates (ESU) program. To activate a Multiple Activation Key (MAK) for ESU, machines must…
2 articles · Updated November 6, 2025 -
Multiple Vulnerabilities Identified in Microsoft Products (CVE-2025)
A series of vulnerabilities, collectively identified as CVE-2025, have been reported across various Microsoft products, including Windows, Office, and Azure. These vulnerabilities range from privilege escalation to code…
73 articles · Updated November 21, 2025
Recent Intelligence Reports
- Cisa Flags Microsoft Configmgr Rce Flaw As Exploited In Attacks — www.bleepingcomputer.com · August 14, 2026
- SentinelOne CVE-2026-47301 advisory — www.sentinelone.com · August 14, 2026
- Critical Microsoft bug from 2024 under exploitation — Theregister · February 13, 2026
- Attackers finally get around to exploiting critical Microsoft bug from 2024 — Theregister · February 13, 2026
- CISA Warns of Actively Exploited SQL Injection Flaw in Microsoft Configuration Manager — Cyberpress · February 13, 2026
- U.S. CISA adds SolarWinds Web Help Desk, Notepad++, Microsoft Configuration Manager, and Apple devices flaws to its Known Exploited Vulnerabilities catalog — Securityaffairs.Co · February 13, 2026
- CISA Issues Urgent Warning on Microsoft Configuration Manager SQL Injection Vulnerability Under Active Exploitation — Gbhackers · February 13, 2026
- CVE-2025 — Api.Msrc.Microsoft · November 11, 2025