Saturday, February 14, 2026
CISA Exploit List

CISA Active Exploit List – February Update

by Artie Kaye

The US Cybersecurity and Infrastructure Security Agency (CISA) has added several items to its list of must-address exploits. As these are actively being used by attackers in the wild, it is recommended to resolve the issues as soon as possible. Below are the companies, CVE numbers, and links to solutions for said problems. All links open in a new tab or window.

CompanyCVEPlatformDetails
CWPCVE-2022-44877Control Web Panelhttps://control-webpanel.com/changelog#1669855527714-450fb335-6194
MicrosoftCVE-2023-21674Windowshttps://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-21674
CVE-2022-41080Exchange Serverhttps://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-41080
OracleCVE-2023-21587E-Business Suitehttps://www.oracle.com/security-alerts/cpuoct2022.html
Sugar CRMCVE-2023-22952Multiple Productshttps://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2023-001/
TelerikCVE-2017-11357UI for ASP.NET AJAZhttps://docs.telerik.com/devtools/aspnet-ajax/knowledge-base/asyncupload-insecure-direct-object-reference
ZohoCVE-2022-47966ManageEnginehttps://www.manageengine.com/security/advisory/CVE/cve-2022-47966.html

For a more comprehensive list of all vulnerabilities, visit cisa.gov (Opens in a new tab/window.)