Active Exploitation
#threatreport #MediumCompleteness
January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day | 24-02-2026
Source: https://www.recordedfuture.com/blog/january-2026-cve-landscape
Key details below ↓
🧑💻Actors/Campaigns:
Fancy_bear
Neusploit
💀Threats:
Nuclei_tool, Minidoor, Pixynetloader, Covenant_c2_tool, Grunt, Com_hijacking_technique, Supply_chain_technique,
🎯Victims: Enterprise communication platforms, Enterprise management platforms, Government users, Business users, Wordpress sites, Email systems
🏭Industry: Government
🌐Geo: Russian
🔓CVEs: CVE-2026-23760 \[[Vulners](https://vulners.com/cve/CVE-2026-23760)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: True
Soft:
- smartertools smartermail (<100.0.9511)
CVE-2025-34026 \[[Vulners](https://vulners.com/cve/CVE-2025-34026)]
- CVSS V3.1: *7.5*,
- Vulners: Exploitation: True
Soft:
- versa-networks concerto (<12.1.2, 12.2.0)
CVE-2009-0556 \[[Vulners](https://vulners.com/cve/CVE-2009-0556)]
- CVSS V3.1: *8.8*,
- Vulners: Exploitation: True
Soft:
- microsoft office_powerpoint (2004)
- microsoft powerpoint (2000, 2002, 2003)
CVE-2025-8110 \[[Vulners](https://vulners.com/cve/CVE-2025-8110)]
- CVSS V3.1: *8.8*,
- Vulners: Exploitation: True
Soft:
- gogs (le0.13.3)
CVE-2026-24423 \[[Vulners](https://vulners.com/cve/CVE-2026-24423)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: True
Soft:
- smartertools smartermail (<100.0.9511)
CVE-2025-68645 \[[Vulners](https://vulners.com/cve/CVE-2025-68645)]
- CVSS V3.1: *8.8*,
- Vulners: Exploitation: True
Soft:
- synacor zimbra_collaboration_suite (<10.0.18, <10.1.13)
CVE-2018-14634 \[[Vulners](https://vulners.com/cve/CVE-2018-14634)]
- CVSS V3.1: *7.8*,
- Vulners: Exploitation: True
Soft:
- paloaltonetworks pan-os (<7.1.23, <8.0.16, <8.1.7)
CVE-2026-21509 \[[Vulners](https://vulners.com/cve/CVE-2026-21509)]
- CVSS V3.1: *7.8*,
- Vulners: Exploitation: True
Soft:
- microsoft 365_apps (-)
- microsoft office (2016, 2019)
- microsoft office_long_term_servicing_channel (2021, 2024)
CVE-2025-37164 \[[Vulners](https://vulners.com/cve/CVE-2025-37164)]
- CVSS V3.1: *10.0*,
- Vulners: Exploitation: True
Soft:
- hpe oneview (le10.20.00)
CVE-2026-1340 \[[Vulners](https://vulners.com/cve/CVE-2026-1340)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: True
Soft:
- ivanti endpoint_manager_mobile (le12.7.0.0)
CVE-2026-1281 \[[Vulners](https://vulners.com/cve/CVE-2026-1281)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: True
Soft:
- ivanti endpoint_manager_mobile (le12.5.0.0, 12.5.1.0, 12.6.0.0, 12.6.1.0, 12.7.0.0)
CVE-2026-20045 \[[Vulners](https://vulners.com/cve/CVE-2026-20045)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: True
Soft:
- cisco unified_communications_manager (<14su5, le15su3a)
- cisco unified_communications_manager_im_and_presence_service (<14su5, le15su3a)
- cisco unity_connection (<14su5, le15su3)
CVE-2026-20931 \[[Vulners](https://vulners.com/cve/CVE-2026-20931)]
- CVSS V3.1: *8.0*,
- Vulners: Exploitation: Unknown
Soft:
- microsoft windows_10_1607 (<10.0.14393.8783)
- microsoft windows_10_1809 (<10.0.17763.8276)
- microsoft windows_10_21h2 (<10.0.19044.6809)
- microsoft windows_10_22h2 (<10.0.19045.6809)
...
CVE-2026-20805 \[[Vulners](https://vulners.com/cve/CVE-2026-20805)]
- CVSS V3.1: *5.5*,
- Vulners: Exploitation: True
Soft:
- microsoft windows_10_1607 (<10.0.14393.8783)
- microsoft windows_10_1809 (<10.0.17763.8276)
- microsoft windows_10_21h2 (<10.0.19044.6809)
- microsoft windows_10_22h2 (<10.0.19045.6809)
...
CVE-2025-52691 \[[Vulners](https://vulners.com/cve/CVE-2025-52691)]
- CVSS V3.1: *10.0*,
- Vulners: Exploitation: True
Soft:
- smartertools smartermail (<100.0.9413)
CVE-2025-31125 \[[Vulners](https://vulners.com/cve/CVE-2025-31125)]
- CVSS V3.1: *7.5*,
- Vulners: Exploitation: True
Soft:
- vitejs vite (<4.5.11, <5.4.16, <6.0.13, <6.1.3, <6.2.4)
CVE-2026-24858 \[[Vulners](https://vulners.com/cve/CVE-2026-24858)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: True
Soft:
- fortinet fortianalyzer (le7.0.15, le7.2.11, <7.4.10, <7.6.6)
- fortinet fortimanager (le7.0.15, le7.2.11, <7.4.10, <7.6.6)
- fortinet fortiproxy (le7.0.22, le7.2.15, le7.4.12, le7.6.4)
- fortinet fortiweb (le7.4.11, le7.6.6, le8.0.3)
...
CVE-2025-54313 \[[Vulners](https://vulners.com/cve/CVE-2025-54313)]
- CVSS V3.1: *7.5*,
- Vulners: Exploitation: True
Soft:
- prettier eslint-config-prettier (8.10.1, 9.1.1, 10.1.6, 10.1.7)
CVE-2025-40551 \[[Vulners](https://vulners.com/cve/CVE-2025-40551)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: True
Soft:
- solarwinds web_help_desk (<2026.1)
CVE-2026-20029 \[[Vulners](https://vulners.com/cve/CVE-2026-20029)]
- CVSS V3.1: *4.9*,
- Vulners: Exploitation: Unknown
CVE-2026-23550 \[[Vulners](https://vulners.com/cve/CVE-2026-23550)]
- CVSS V3.1: *10.0*,
- Vulners: Exploitation: Unknown
CVE-2026-23800 \[[Vulners](https://vulners.com/cve/CVE-2026-23800)]
- CVSS V3.1: *10.0*,
- Vulners: Exploitation: Unknown
CVE-2024-37079 \[[Vulners](https://vulners.com/cve/CVE-2024-37079)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: True
Soft:
- vmware cloud_foundation (<5.2)
CVE-2026-24061 \[[Vulners](https://vulners.com/cve/CVE-2026-24061)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: True
Soft:
- gnu inetutils (le2.7)
🤖LLM extracted TTPs:`
T1005, T1027, T1053.005, T1071.001, T1078, T1090, T1098, T1112, T1114.003, T1133, ...
🧨IOCs:
- Path: 2
- Registry: 1
- IP: 6
- Email: 4
- File: 2
💽Software: Microsoft Office, Ivanti, Linux, Zimbra Collaboration Suite, WordPress, Outlook, Ivanti EPMM
🔢Algorithms: xor
📜Programming Languages: php
#threatreport:
In January 2026, there was a noted 5% increase in critical vulnerabilities, with 23 high-impact issues identified. Among these, the exploitation of a significant Microsoft Office zero-day vulnerability (CVE-2026-21509) by Russian state-sponsored group APT28 highlighted ongoing threats to enterprise technologies. This vulnerability, which relates to the reliance on untrusted inputs in security decisions, enabled APT28 to utilize weaponized Rich Text Format (RTF) files to deliver various malicious implants, including MiniDoor, PixyNetLoader, and Covenant Grunt.
The exploitation chain initiated with an RTF file that bypassed Office OLE mitigations. The attackers deployed MiniDoor as an Outlook VBA script for email collection, while PixyNetLoader, which created a mutex for persistence, allowed further attacks. A notable aspect of this operation was the use of geography-based evasion to limit the delivery of the malicious payloads, demonstrating the sophistication of the APT28 attacks.
In addition to Microsoft, other vendors such as SmarterTools and Ivanti were significantly affected, with SmarterTools reporting multiple critical vulnerabilities allowing authentication bypass and remote code execution (RCE). Specifically, CVE-2026-23760 identified a privilege escalation flaw in SmarterMail, permitting unauthenticated users to reset passwords, demonstrating serious flaws in expected security protocols.
Furthermore, the Modular DS WordPress plugin was found to have multiple vulnerabilities, CVE-2026-23550 and CVE-2026-23800, that allowed attackers to gain administrator access without authentication. These vulnerabilities emphasize the risk of widespread exploitation due to the centralized management of multiple WordPress sites.
Post summary
The report highlights active exploitation of Microsoft Office zero‑day CVE‑2026‑21509 by APT28, detailing the RTF-based attack chain and associated tools, while also noting related critical vulnerabilities in SmarterTools and WordPress.