Microsoft Fixes Six Exploited Bugs in February Patch Tuesday Updates
The exploited vulnerabilities in question exist across various products, from Microsoft Word to Windows Shell.
The exploited vulnerabilities in question exist across various products, from Microsoft Word to Windows Shell.
UNC3886 is a Chinese espionage group known for targeting defense, tech, and telecom organizations across both the U.S. and Asia-Pacific-Japan regions.
CISA said potential exploitation of flaws in unsupported edge devices creates "a significant threat to federal property."
The series of incidents detailed by Mandiant researchers started in early to mid-January, and included a previously disclosed campaign involving Okta customers.
The vulnerabilities (CVE-2026-1281 and CVE-2026-1340) could lead to unauthenticated remote code execution if successfully exploited.
Fortinet is rolling out updates for CVE-2026-24858, with fixes for some versions available as of Tuesday, and others in releases that are upcoming at an unspecified date.