← Back to list

Threat and Vulnerabilities Report-February 2026

Executive Summary

Loginsoft · 2026-03-03 14:50 · 0 claps · 2.1 min read
#cybersecurity #lovi #vulnerabilityintelligence #february-2026 #activeexploitation
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity 🥊 · Combat Sports

Threat and Vulnerabilities Report-February 2026

Executive Summary

February closed with a concentrated surge in exploited vulnerabilities and ransomware activity, signaling intensified adversary focus on high-impact enterprise targets. A total of 28 vulnerabilities were added to the CISA Known Exploited Vulnerabilities (KEV) catalog, with Microsoft accounting for eight entries, followed by multiple additions impacting Cisco, Roundcube, Sangoma FreePBX, GitLab, and SolarWinds, alongside individual entries affecting Apple, Dell, and Google. Beyond KEV updates, active exploitation activity was observed across widely deployed platforms including RARLAB WinRAR, the Linux Kernel, Atlassian Crowd, Hotta Studio products, and Microsoft Office demonstrating adversaries’ continued preference for both enterprise-grade software and legacy attack surfaces. On the ransomware front, Qilin led activity with 110 victim disclosures, followed by The Gentlemen (83) and Clop (79), underscoring sustained extortion pressure. Healthcare, education, and manufacturing sectors remained primary targets, as threat actors combined newly disclosed flaws with long-standing vulnerabilities to establish access, exfiltrate data, and maximize operational disruption.

Vulnerabilities added to the CISA KEV catalog in February 2026

February 2026 recorded 28 new additions to the CISA Known Exploited Vulnerabilities (KEV) catalog, a notable increase from 17 entries in January, signaling an acceleration in confirmed exploitation activity. The newly listed vulnerabilities affected major vendors including Microsoft, Cisco, Roundcube, Sangoma FreePBX, GitLab, SolarWinds, Apple, Dell, and Google, reflecting sustained attacker focus on enterprise platforms, network infrastructure, and externally exposed management systems. The month-over-month rise highlights the shrinking gap between vulnerability disclosure and active abuse. This upward trend reinforces the need for organizations to prioritize KEV-aligned patching and continuously monitor real-world exploitation patterns.

Actively Exploited Vulnerabilities in February 2026

February 2026 witnessed sustained real-world exploitation across widely deployed enterprise and endpoint technologies, reinforcing the operational tempo seen in recent months. Active abuse was observed in products such as RARLAB WinRAR, the Linux Kernel, Atlassian Crowd, Hotta Studio platforms, and Microsoft Office, demonstrating attacker focus on both server-side infrastructure and user-facing applications. The exploitation patterns indicate continued reliance on a mix of newly disclosed flaws and long-standing vulnerabilities to gain initial access and establish persistence. This trend underscores how rapidly adversaries operationalize technical weaknesses across diverse environments, particularly where patching delays or legacy components remain present.

Ransomware Insights for February 2026

February 2026 saw sustained ransomware momentum, with Qilin emerging as the most active group, followed closely by The Gentlemen and Clop, reflecting continued competition among major extortion operations. Activity levels indicate a structured targeting approach rather than opportunistic attacks, with healthcare, education, and manufacturing sectors experiencing consistent pressure. Threat actors combined vulnerability exploitation, credential abuse, and data exfiltration to strengthen double-extortion leverage. The month’s trends reinforce that ransomware operations are operating at scale, aligning technical intrusion methods with financial disruption strategies to maximize impact and payout potential.

Conclusion

February’s threat activity makes one point unmistakably clear: adversaries are optimizing speed, scale, and precision. From enterprise software exploitation to sustained ransomware campaigns targeting healthcare, education, and manufacturing, attackers are blending fresh disclosures with older weaknesses to maximize operational impact. Reactive patching is no longer sufficient in an environment where exploitation timelines continue to shrink. Organizations require continuous visibility into active threats, exploitation patterns, and sector-specific risk exposure. Loginsoft Vulnerability Intelligence (LOVI) empowers security teams to anticipate, prioritize, and respond with clarity transforming threat intelligence into decisive defensive action.

For more details, check out the full report.


메타데이터
post_id
74f1ab2a1bce
slug
threat-and-vulnerabilities-report-february-2026-74f1ab2a1bce
url
https://medium.com/@Loginsoft/threat-and-vulnerabilities-report-february-2026-74f1ab2a1bce
canonical_url
https://medium.com/@Loginsoft/threat-and-vulnerabilities-report-february-2026-74f1ab2a1bce
author_url
https://medium.com/@Loginsoft
status
ok
fetched_at
2026-06-20 20:29:01