← Carolina Clear Tech

Cyber Threat Brief

2026-02-21

Listen to this brief (12:47)

Download MP3
Show Notes

Show Notes - 2026-02-21

Stories Covered

CVEs Referenced

CVE-2020-36426, CVE-2021-24119, CVE-2022-27781, CVE-2022-27782, CVE-2024-11738, CVE-2024-4577, CVE-2024-46686, CVE-2024-46742, CVE-2024-46795, CVE-2024-46796, CVE-2024-47191, CVE-2024-53186, CVE-2024-55549, CVE-2024-8926, CVE-2024-9632, CVE-2025-13034, CVE-2025-14017, CVE-2025-14819, CVE-2025-15444, CVE-2025-49113, CVE-2025-58436, CVE-2025-61727, CVE-2025-61729, CVE-2025-66382, CVE-2025-68461, CVE-2025-68753, CVE-2025-68755, CVE-2025-68758, CVE-2025-68763, CVE-2025-68766, CVE-2025-68771, CVE-2025-68781, CVE-2025-68786, CVE-2025-68808, CVE-2025-68817, CVE-2025-68823, CVE-2025-71066, CVE-2025-71109, CVE-2025-71114, CVE-2025-71133, CVE-2025-71143, CVE-2026-21860

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Security Brief - February 21, 2026

Today: CISA adds two actively exploited Roundcube webmail flaws to KEV catalog with March 13 remediation deadline. Microsoft published CVE-2024-8926, a bypass for the previously exploited PHP CGI vulnerability CVE-2024-4577 that has ransomware links. Over 30 Linux kernel and library vulnerabilities disclosed across SMB, TLS, crypto, and device driver components.

Critical Alerts

CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog (CVE-2025-49113, CVE-2025-68461)

CISA added two Roundcube webmail vulnerabilities to the KEV catalog on February 20. CVE-2025-49113 (CVSS 9.9) is a deserialization flaw allowing remote code execution by authenticated users through unvalidated URL parameters in the settings upload handler. The vulnerability has EPSS 0.921 (100th percentile) and was hidden in the codebase for over 10 years before discovery. FearsOff researchers confirmed attackers weaponized the exploit within 48 hours of disclosure, and exploits were sold publicly on June 4, 2025. CVE-2025-68461 (CVSS 7.2) is an XSS vulnerability via SVG animate tags. Both flaws were fixed in June and December 2025 respectively. Nation-state groups APT28 and Winter Vivern have previously exploited Roundcube vulnerabilities.

Vulnerability Disclosures

PHP CGI Parameter Injection Bypass (CVE-2024-8926)

Microsoft published information on CVE-2024-8926, a bypass for CVE-2024-4577, the PHP CGI parameter injection vulnerability previously added to CISA KEV with ransomware links. CVE-2024-4577 has EPSS 0.944 (100th percentile) and a CISA KEV remediation deadline that passed in July 2024. CVE-2024-8926 carries EPSS 0.022 (84th percentile), indicating attackers have discovered a method to circumvent the original patch.

Linux Kernel SMB/CIFS Vulnerabilities

Microsoft disclosed multiple Linux kernel vulnerabilities affecting SMB/CIFS client and server implementations. CVE-2024-53186 is a use-after-free in ksmbd request handling. CVE-2024-46686 involves null pointer dereference in smb2_new_read_req(). CVE-2024-46742 is a potential null pointer dereference in smb2_open() lease context handling. CVE-2024-46796 is a double-put bug in smb2_set_path_size(). CVE-2024-46795 affects connection binding marks in ksmbd. CVE-2025-68817 is a use-after-free under concurrency in ksmbd_tree_connect_put. CVE-2025-68786 addresses lock-range size underflow issues. All carry low EPSS scores (0.000-0.001) but affect core file-sharing functionality.

TLS and Certificate Validation Vulnerabilities

Multiple TLS and certificate handling vulnerabilities published. CVE-2025-13034 affects QUIC certificate pinning with GnuTLS. CVE-2025-14017 involves broken TLS options for threaded LDAPS connections. CVE-2025-61727 addresses improper DNS name constraint validation for wildcard certificates in Go's crypto/x509. CVE-2022-27782 affects libcurl TLS/SSH connection reuse, incorrectly matching connections despite changed security settings. CVE-2025-14819 is an OpenSSL partial chain store policy bypass. All carry minimal EPSS scores but affect fundamental encryption and identity validation.

Privilege Escalation and Memory Corruption Flaws

CVE-2024-47191 in oath-toolkit 2.6.7-2.6.11 allows root privilege escalation through symlink mishandling in pam_oath.so during PAM authentication. CVE-2024-9632 is a heap-based buffer overflow in TigerVNC/Xorg-x11-server enabling privilege escalation. CVE-2024-55549 is a use-after-free in libxslt before 1.1.43. CVE-2025-61729 causes excessive resource consumption in Go's crypto/x509 error string generation. CVE-2026-21860 affects Werkzeug safe_join() allowing Windows special device names with compound extensions.

Denial of Service Vulnerabilities

CVE-2025-58436 in CUPS allows slow client connections to halt cupsd, enabling DoS attacks. CVE-2025-66382 in libexpat through 2.7.3 allows crafted 2 MiB files to consume dozens of seconds of processing time. CVE-2024-11738 in Rustls causes network-reachable panic in acceptor::accept. CVE-2022-27781 in libcurl with NSS creates infinite loops when retrieving certificate information.

Additional Linux Kernel Vulnerabilities

Over 15 additional Linux kernel CVEs disclosed covering crypto drivers (CVE-2025-68763), display backlight (CVE-2025-68758), filesystem operations (CVE-2025-68771), network drivers (CVE-2025-71133), watchdog timers (CVE-2025-71114), MIPS architecture (CVE-2025-71109), clock management (CVE-2025-71143), audio (CVE-2025-68753), USB (CVE-2025-68781), media subsystems (CVE-2025-68808), and network scheduling (CVE-2025-71066). All carry minimal EPSS scores.

Historic TLS/Crypto Library Vulnerabilities

CVE-2021-24119 in Mbed TLS 2.24.0 is a side-channel vulnerability in base64 PEM decoding allowing RSA key extraction in SGX environments. CVE-2020-36426 is a buffer over-read in mbedtls_x509_crl_parse_der. Both have EPSS 0.009 (76th percentile) and affect embedded systems and IoT devices.

Perl Cryptography Module Vulnerability (CVE-2025-15444)

Crypt::Sodium::XS module versions before 0.000042 for Perl include a vulnerable version of libsodium.

Trends & Context

Today's disclosure set is dominated by Linux kernel and library vulnerabilities affecting fundamental networking, encryption, and authentication components. The Roundcube KEV additions highlight continued targeting of webmail platforms by nation-state actors. The PHP CVE-2024-8926 bypass demonstrates attackers developing workarounds for previously patched ransomware-linked vulnerabilities. Organizations running Linux infrastructure, particularly for file sharing, web services, and authentication, should prioritize kernel and library updates.