CVE-2024-43468Active Exploitation(microsoft / configuration_manager_2403)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 10 mentions and remains active

Immediate actions

  • Patch microsoft configuration_manager_2403 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Microsoft Configuration Manager Remote Code Execution Vulnerability

5.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-05. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • configuration_manager_2403
  • configuration_manager_2409
  • configuration_manager_2503

Threat summary

  • Active exploitation appears in 28 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 39 mentions across 13 observed days

What's happening

  • Active exploitation reported across 28 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 21 signals
  • Technical details provided in 27 signals
  • Disclosure: 4 classified signals
  • Peaked 11d ago at 10 mentions (2026-02-13); latest day: 1
  • 39 total mentions across 13 days

Affected systems

Vendors
Products
configuration_manager_2403configuration_manager_2409configuration_manager_2503

1 version affected across 3 products

Deep dive

Activity timeline39 mentions / 13d
035810Mentions · 2026-02-12: 4Mentions · 2026-02-13: 10Mentions · 2026-02-14: 6Mentions · 2026-02-15: 3Mentions · 2026-02-16: 3Mentions · 2026-02-17: 1Mentions · 2026-02-18: 2Mentions · 2026-02-19: 1Mentions · 2026-02-24: 1Mentions · 2026-03-07: 2Mentions · 2026-03-10: 1Mentions · 2026-05-04: 4Mentions · 2026-08-05: 1PoC Mentioned / Linked · 2026-02-13: 2PoC Mentioned / Linked · 2026-02-15: 1PoC Mentioned / Linked · 2026-02-16: 1PoC Mentioned / Linked · 2026-05-04: 1Active Exploitation · 2026-02-12: 2Active Exploitation · 2026-02-13: 8Active Exploitation · 2026-02-14: 5Active Exploitation · 2026-02-15: 2Active Exploitation · 2026-02-16: 3Active Exploitation · 2026-02-17: 1Active Exploitation · 2026-02-18: 1Active Exploitation · 2026-02-19: 1Active Exploitation · 2026-03-07: 1Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-05-04: 3Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-02-13: 7Patch / Workaround · 2026-02-14: 5Patch / Workaround · 2026-02-15: 2Patch / Workaround · 2026-02-16: 2Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-03-07: 1Patch / Workaround · 2026-05-04: 1Technical Details · 2026-02-12: 3Technical Details · 2026-02-13: 6Technical Details · 2026-02-14: 6Technical Details · 2026-02-15: 3Technical Details · 2026-02-16: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-18: 2Technical Details · 2026-03-07: 2Technical Details · 2026-03-10: 1Technical Details · 2026-05-04: 202-1202-1302-1402-1502-1602-1702-1802-1902-2403-0703-1005-0408-05
Signal classification5 categories
Active Exploitation
2564.1%
Patch
512.8%
Disclosure
410.3%
General
410.3%
Exploit
12.6%
Referenced assets57 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-124
Active Exploitation2Disclosure1Patch1
2026-02-1310
Active Exploitation7Exploit1General1Patch1
2026-02-146
Active Exploitation4Patch2
2026-02-153
Active Exploitation2Disclosure1
2026-02-163
Active Exploitation2General1
2026-02-171
Active Exploitation1
2026-02-182
Active Exploitation1Disclosure1
2026-02-191
Active Exploitation1
2026-02-241
General1
2026-03-072
Active Exploitation1Patch1
2026-03-101
Active Exploitation1
2026-05-044
Active Exploitation3Disclosure1
2026-08-051
General1
Full discourse20 posts
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CISA has added 3 vulnerabilities to the KEV Catalog CVE-2025-15556: Notepad++ Download of Code Without Integrity Check Vulnerability: Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to download and execute an attacker-controlled installer. This could lead to arbitrary code execution with the privileges of the user. CVE-2026-20700: Apple Multiple Buffer Overflow Vulnerability: Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow an attacker with memory write the capability to execute arbitrary code. CVE-2024-43468: Microsoft Configuration Manager SQL Injection Vulnerability: Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment which are processed in an unsafe manner enabling the attacker to execute commands on the server and/or underlying database.

    Post summary

    CISA announced the addition of three new CVEs to its KEV catalog, detailing their technical aspects but providing no evidence of PoC, exploit code, active exploitation, or available patches.

    02411183715.8K
    164.8K followersView on X
  • CISA Cyber@CISACyber
    Patch

    🛡️ We added Microsoft vulnerability CVE-2024-43468, Notepad++ vulnerability CVE-2025-15556, SolarWinds vulnerability CVE 2025-40536, & Apple vulnerability CVE-2026-20700 to our KEV Catalog. Apply mitigations to protect your org from cyberattacks. https://go.dhs.gov/Z3Q https://t.co/0hbYVOzt7p

    Post summary

    The post announces that several CVEs have been added to the KEV catalog and urges users to apply mitigations to protect against potential exploitation.

    53838598.5K
    291.8K followersView on X
  • Andre Gironda@AndreGironda
    Active Exploitation

    Attackers finally get around to exploiting critical Microsoft bug CVE-2024-43468 from 2024 -- https://www.theregister.com/2026/02/13/critical_microsoft_bug_from_2024/

    Post summary

    Attackers have begun exploiting CVE‑2024‑43468 in the wild, indicating ongoing exploitation of this critical Microsoft flaw.

    02080432
    3.6K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(2/12追加) 🛡️No.1515 CVE-2024-43468 Microsoft Configuration Manager SQL Injection Vulnerability ============= CVSSスコア: 9.8 (Base) / Microsoft Corporation CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:SQLインジェクション (CWE-89 / Microsoft Corporation) 深刻度:緊急🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、特別に細工されたリクエストを受信することで、サーバーや基盤となるデータベース上でコマンドを実行される恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43468 🛡️No.1516 CVE-2025-15556 Notepad++ Download of Code Without Integrity Check Vulnerability ============= CVSSスコア: 7.7 (Base) / VulnCheck CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N 種別:ダウンロードしたコードの完全性検証不備 (CWE-494 / VulnCheck) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、アップデートトラフィックを傍受またはリダイレクトして、攻撃者が制御するインストーラをダウンロード・実行される恐れがあります。この脆弱性を悪用することで、ユーザー権限で任意のコードが実行される可能性があります。 https://notepad-plus-plus.org/news/clarification-security-incident/ https://community.notepad-plus-plus.org/topic/27298/notepad-v8-8-9-vulnerability-fix 🛡️No.1517 CVE-2025-40536 SolarWinds Web Help Desk Security Control Bypass Vulnerability ============= CVSSスコア: 8.1 (Base) / SolarWinds CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:保護メカニズムの不具合 (CWE-693 / SolarWinds) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、リモートから制限された特定機能にアクセスされる恐れがあります。 https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40536 🛡️No.1518 CVE-2026-20700 Apple Multiple Buffer Overflow Vulnerability ============= CVSSスコア: 7.8 (Base) / CISA-ADP CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 種別:バッファエラー (CWE-119 / CISA-ADP) 深刻度:重要 ---------------------- 悪用時影響: メモリへの書き込み権限を持つ攻撃者により、ローカル上で任意のコードを実行される恐れがあります。 https://support.apple.com/en-us/126346 https://support.apple.com/en-us/126348 https://support.apple.com/en-us/126351 https://support.apple.com/en-us/126352 https://support.apple.com/en-us/126353 CISA Adds Four Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/02/12/cisa-adds-four-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The post announces four CVEs that CISA has confirmed are actively exploited, providing vendor advisory links and technical details but no PoC or exploit code.

    000803.7K
    42.5K followersView on X
  • SC Media@SCMagazine
    Active Exploitation

    The @CISAgov added 4 exploited bugs to KEV: SolarWinds WHD (CVE-2025-40536, 9.8), MS ConfigMgr SQLi→RCE (CVE-2024-43468, 9.8), Apple (CVE-2026-20700), Notepad++ (CVE-2025-15556). Patch fast. #cybersecurity #CISO #infosec #ITsecurity https://bit.ly/4azGT9e

    Post summary

    CISA has added four CVEs to its KEV list as known exploited bugs, highlighting high severity scores and urging rapid patching.

    020201.8K
    119.3K followersView on X
  • Mr.Rabbit@01ra66it
    Active Exploitation

    【Microsoft Configuration Manager(CVE-2024-43468)KEV:管理基盤SQLiが「全端末支配」に直結】 Microsoft Configuration ManagerのSQLインジェクション(CVE-2024-43468)がKEVとして扱われ、実悪用が進行中と整理された。 ConfigMgrは端末管理・配布・設定の中枢であり、侵害されると“配下の多数端末に対する横断的支配”へ直結する。攻撃者視点では、1台ずつ侵害するよりも管理基盤を落とす方がROIが高い。 能力変化としては、攻撃者が「侵入→横移動」より「侵入→管理プレーン掌握→一括展開」へ寄せている点が重要となる。管理サーバの露出面と権限境界が、そのまま組織リスクになる。 #KEV #Microsoft #ConfigMgr #CVE-2024-43468 https://gbhackers.com/cisa-issues-urgent-warning-on-microsoft-configuration-manager/

    Post summary

    The post announces that Microsoft Configuration Manager’s CVE-2024-43468 (an SQL injection) is a KEV with active exploitation underway, underscoring the risk of full system compromise through the management plane.

    11010354
    3.4K followersView on X
  • Machina Record@MachinaRecord
    General

    【リンク集:2月13日〜16日のセキュリティ関連ニュース/記事】 <脆弱性> ・米CISA、Microsoft SCCMの深刻な脆弱性が攻撃に悪用されたと警告(CVE-2024-43468) https://www.bleepingcomputer.com/news/security/cisa-flags-microsoft-configmgr-rce-flaw-as-exploited-in-attacks/ ・Chrome 145、11件の脆弱性を修正(CVE-2026-2313、CVE-2026-2314他) https://www.securityweek.com/chrome-145-patches-11-vulnerabilities/ ・Ivanti製品の脆弱性を狙ったRCE攻撃、83%は単一の脅威アクターによる犯行か(CVE-2026-1281、CVE-2026-1340) https://www.bleepingcomputer.com/news/security/one-threat-actor-responsible-for-83-percent-of-recent-ivanti-rce-attacks/ ・BeyondTrustの脆弱性、PoC公開直後から悪用が確認される(CVE-2026-1731) https://securityaffairs.com/187962/uncategorized/attackers-exploit-beyondtrust-cve-2026-1731-within-hours-of-poc-release.html <マルウェア・その他脅威> ・UAT-9921がVoidLinkマルウェアを展開、標的はテクノロジーおよび金融部門https://thehackernews.com/2026/02/uat-9921-deploys-voidlink-malware-to.html ・認証情報盗むChrome拡張機能を見つけて削除する方法 https://www.malwarebytes.com/blog/news/2026/02/how-to-find-and-remove-credential-stealing-chrome-extensions ・ユーザーデータをリーク・窃取する有害なChrome拡張機能が300超見つかる https://www.securityweek.com/over-300-malicious-chrome-extensions-caught-leaking-or-stealing-user-data/ ・ClickFix攻撃でClaude LLMのアーティファクトが悪用される Macにインフォスティーラーを拡散 https://www.bleepingcomputer.com/news/security/claude-llm-artifacts-abused-to-push-mac-infostealers-in-clickfix-attack/ ・TrezorとLedgerのユーザーの暗号資産狙う郵便物 https://www.bleepingcomputer.com/news/security/snail-mail-letters-target-trezor-and-ledger-users-in-crypto-theft-attacks/ <データ侵害/サイバー犯罪> ・オランダ大手通信会社Odidoがデータ侵害を受ける 顧客620万人に影響 https://techcrunch.com/2026/02/13/dutch-phone-giant-odido-says-millions-of-customers-affected-by-data-breach/ ・フィンテック企業Figureがデータ侵害を公表 従業員がフィッシング攻撃の被害にhttps://securityaffairs.com/187988/cyber-crime/fintech-firm-figure-disclosed-data-breach-after-employee-phishing-attack.html <AI関連> ・設定ミスのあるAIが国家のインフラ崩壊を引き起こす可能性 https://www.theregister.com/2026/02/13/gartner_ai_infrastructure/ <サイバー戦/APT/国家型アクター/地政学関連> ・ロシア系アクターがウクライナへのCANFAILマルウェア攻撃に関与か Googleが指摘 https://thehackernews.com/2026/02/google-ties-suspected-russian-actor-to.html <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・韓国、データ侵害許したルイヴィトン・ディオール・ティファニーに罰金2,500万ドルを科すhttps://www.bleepingcomputer.com/news/security/louis-vuitton-dior-and-tiffany-fined-25-million-over-data-breaches/ <プライバシー> ・米国土安全保障省、反ICEアカウントの所有者特定へ圧力強化 多くの行政召喚状を送付かhttps://techcrunch.com/2026/02/14/homeland-security-reportedly-sent-hundreds-of-subpoenas-seeking-to-unmask-anti-ice-accounts/ ・Amazon傘下のRingがFlockとの提携計画を終了 プライバシー侵害懸念されるカメラの宣伝騒動から数日後 https://therecord.media/ring-ends-partnership-with-flock-superbowl-ad <リサーチ/攻撃手法/TTP> ・PastebinのコメントがJavaScript使うClickFix攻撃を促進、暗号資産スワップを乗っ取るhttps://www.bleepingcomputer.com/news/security/pastebin-comments-push-clickfix-javascript-attack-to-hijack-crypto-swaps/ ・マイクロソフト、DNSベースのClickFix攻撃の詳細を公開 マルウェアのステージングにNslookupコマンドを使用 https://thehackernews.com/2026/02/microsoft-discloses-dns-based-clickfix.html ・北朝鮮の偽リクルーター、開発者向けコーディング課題にマルウェアを潜ませる https://www.bleepingcomputer.com/news/security/fake-job-recruiters-hide-malware-in-developer-coding-challenges/ ・CRMのコアアプリケーションを攻撃せずに200万件以上のレコードと文書を侵害する方法 https://www.catchify.sa/post/leaking-2m-records-third-party-misconfiguration <政府/政策> ・欧州社会は「恒久的な」サイバー脅威やハイブリッド脅威に適応する必要がある スウェーデンが警告 https://therecord.media/sweden-cyber-threats-europe-permanent ・米国務省サイバー担当官、攻撃者に「実際の代償」を支払わせるべきと主張 https://therecord.media/usa-cyber-actors-consequences ・エストニア諜報機関長官、攻撃的サイバー能力への投資を欧州各国に呼び掛け https://therecord.media/estonia-spy-chief-calls-on-europe-to-invest-in-own-offense <その他> ・独占:パロアルトがハッキング調査報告書から中国を削除か 同国の報復を憂慮した可能性も https://www.reuters.com/world/china/palo-alto-chose-not-tie-china-hacking-campaign-fear-retaliation-beijing-sources-2026-02-12/ ・エプスタイン文書がEVスタートアップとシリコンバレーについて明らかにするもの https://techcrunch.com/2026/02/15/what-the-epstein-files-reveal-about-ev-startups-and-silicon-valley/

    Post summary

    The entry compiles a range of security news items—including CVE disclosures, patches, and reports of active exploitation—yet lacks detailed technical or tooling information for individual vulnerabilities.

    01011275
    1.2K followersView on X
  • Dr. John D. Johnson@johndjohnson
    Active Exploitation

    CISA Warns of Actively Exploited SQL Injection Flaw in Microsoft Configuration Manager Tracked as CVE-2024-43468, the vulnerability enables remote attackers to execute arbitrary commands on affected servers and underlying databases through specially crafted requests, stemming from improper neutralization of user-supplied input classified under CWE-89. https://nuel.ink/RAukcV

    Post summary

    CISA warns that CVE-2024-43468, a SQL Injection in Microsoft Configuration Manager, is actively exploited in the wild, enabling remote command execution.

    1001075
    1.1K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The vulnerability is a SQL injection (CWE-89) in Microsoft Configuration Manager where specially crafted attacker-supplied requests are processed in an unsafe manner (MITRE) MITRE: CVE-2024-43468. Because the flaw is reachable without authentication, exploitation can begin…

    Post summary

    The text announces a new SQL injection vulnerability in Microsoft Configuration Manager that is reachable without authentication, but offers no PoC, exploit, or patch details.

    1000038
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CISA added CVE-2024-43468 to the Known Exploited Vulnerabilities (KEV) catalog on 2026-02-12, signaling observed exploitation and mandating remediation by federal agencies. This entry covers Microsoft Configuration Manager and is due by 2026-03-05 per CISA’s directive…

    Post summary

    CISA lists CVE-2024-43468 as a known exploited vulnerability in Microsoft Configuration Manager, mandating remediation for federal agencies and confirming active exploitation in the wild.

    1000036
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2024-43468: Unauthenticated SQL injection in Microsoft Configuration Manager enables attacker commands on server and/or database; CISA added CVE-2024-43468 to KEV.

    Post summary

    CISA classified CVE-2024-43468, an unauthenticated SQL injection in Microsoft Configuration Manager, as a known exploited vulnerability.

    1000036
    152 followersView on X
  • Mr.Rabbit@01ra66it
    Active Exploitation

    【Microsoft Configuration Manager(CVE-2024-43468)実悪用:管理基盤SQLiで全社規模侵害の恐れ】 Microsoft Configuration ManagerのSQLインジェクション脆弱性CVE-2024-43468が、実際の攻撃で悪用されている。 この欠陥は未認証で任意コマンド実行につながる。Configuration Managerは大規模端末管理の中枢なので、侵害されると個別端末の被害で終わらず、全社規模での制御奪取に発展しうる。 攻撃者にとっては、管理基盤を1台落とせば多数の端末へ影響を広げられる。効率が良く、ランサムウェアやAPTの両方に好まれる条件が揃っている。 “IT運用ツールは信頼済み”という前提が崩れると、防御側は一気に不利になる。 #KEV #ConfigMgr #SQLi https://gbhackers.com/cisa-issues-urgent-warning-on-microsoft-configuration-manager/

    Post summary

    Microsoft Configuration Manager’s CVE-2024-43468, a SQLi vulnerability enabling unauthenticated command execution, is confirmed to be actively exploited in the wild, potentially allowing full corporate control.

    10000324
    3.4K followersView on X
  • Prateek Tomar@TomarPrateek23
    General

    Just published: Critical Analysis CVE-2024-43468 - Microsoft Configuration Manager SQL.... Practical security guidance from the trenches. Read more: https://threatops.tech/blog/critical-analysis-cve-2024-43468-microsoft-configuration-manager-sql-injection-vulnerability-februar

    Post summary

    The text announces a blog post about CVE-2024-43468, a Microsoft Configuration Manager SQL injection vulnerability, but offers no further details or actionable information.

    0001062
    80 followersView on X
  • SC Media@SCMagazine
    Active Exploitation

    The @CISAgov added 4 exploited bugs to KEV: SolarWinds WHD (CVE-2025-40536, 9.8), MS ConfigMgr SQLi→RCE (CVE-2024-43468, 9.8), Apple (CVE-2026-20700), Notepad++ (CVE-2025-15556). Patch fast. #cybersecurity #CISO #infosec #ITsecurity https://bit.ly/4azGT9e

    Post summary

    CISA added four high‑severity CVEs to its KEV list, noting they are actively exploited; a patch is recommended.

    00010421
    119.3K followersView on X
  • transilienceai@transilienceai
    Active Exploitation

    🚨 These four CVEs were highlighted by CISA KEV for active exploitation risks as of early 2026, emphasizing urgent patching across Microsoft, Notepad++, SolarWinds, and Apple products. Limited technical details or proofs-of-concept are available beyond CVE-2024-43468. #PatchNow #InfoSec

    Post summary

    CISA KEV flagged four CVEs as actively exploited in early 2026, urging immediate patching across Microsoft, Notepad++, SolarWinds, and Apple products, with limited technical details available.

    1000062
    315 followersView on X
  • transilienceai@transilienceai
    Patch

    🚨 **CVE-2024-43468** is a critical SQL injection vulnerability in Microsoft Configuration Manager (ConfigMgr/SCCM), allowing unauthenticated remote attacks via the LocationMgr component. Mitigation involves applying Microsoft's ConfigMgr updates/hotfixes, restricting Management Point (MP) network access, and hunting for anomalous SQL activity. #CyberSecurity #Vulnerability

    Post summary

    The text announces a critical SQL injection vulnerability in Microsoft Configuration Manager and advises applying official updates and network restrictions as mitigation.

    1000062
    315 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Active Exploitation

    CISAが4つの既知の脆弱性をカタログに追加 https://www.cisa.gov/news-events/alerts/2026/02/12/cisa-adds-four-known-exploited-vulnerabilities-catalog CVE-2024-43468 Microsoft Configuration Manager の SQL インジェクション脆弱性 CVE-2025-15556 Notepad++ における整合性チェックなしのコードダウンロードの脆弱性

    Post summary

    CISA has added four known exploited vulnerabilities to its catalog, including CVE‑2024‑43468 (SQL injection in Microsoft Configuration Manager) and CVE‑2025‑15556 (code download without integrity check in Notepad++). No PoC, exploit code, patch, or debunking information is provided.

    10000111
    44 followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISA、既知の悪用された脆弱性4件をカタログに追加 CISA Adds Four Known Exploited Vulnerabilities to Catalog #CISA (Feb 12) CVE-2024-43468 Microsoft Configuration Manager の SQL インジェクション脆弱性 CVE-2025-15556 Notepad++ における整合性チェックなしのコードダウンロードの脆弱性 CVE-2025-40536 SolarWinds Webヘルプデスクのセキュリティ制御バイパスの脆弱性 CVE-2026-20700 Appleの複数のバッファオーバーフロー脆弱性 https://www.cisa.gov/news-events/alerts/2026/02/12/cisa-adds-four-known-exploited-vulnerabilities-catalog

    Post summary

    CISA’s alert adds four CVEs that are already being exploited, but the brief does not provide PoC, exploit code, or patch details.

    00010321
    4.7K followersView on X
  • Polsia@polsia
    General

    Mid-size orgs shouldn't need an SCCM engineer to stay secure. CVE-2024-43468 proved the on-prem stack is a liability. MendBridge runs the endpoint loop. AI agents patch, deploy, and fix compliance drift on Windows, macOS, and Linux. Escalates only when necessary. Live soon.

    Post summary

    The post merely references CVE-2024-43468 without providing any proof of concept, exploitation details, patch information, or technical specifics.

    0000077
    27.0K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://lyrie.ai/research/research/active-exploit-cve-2024-43468-configuration-manager #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The link appears to reference research indicating that CVE-2024-43468 is being actively exploited, though specific exploit details or patches are not provided.

    0000023
    152 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftconfiguration_manager_2403---
Appmicrosoftconfiguration_manager_2409---
Appmicrosoftconfiguration_manager_2503---

Explore more