Wednesday, February 18, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Wednesday's vulnerability disclosures include 7 critical and 48 high-priority CVEs affecting Microsoft Windows, Dell RecoverPoint, WordPress, and Linux systems. Critical CVE volume increased 250% from the prior day while high-priority disclosures nearly doubled with a 92% rise. CVE-2026-22769 carries a maximum CVSS 10 score targeting Dell RecoverPoint, CVE-2026-1937 affects WordPress installations with a 9.8 rating, and CVE-2025-70830 exposes Datart instances using the Freemarker engine at CVSS 9.9. Multiple Microsoft Windows and Office CVEs are confirmed actively exploited, alongside older vulnerabilities in GitLab, Zimbra, and Sangoma FreePBX being leveraged in ongoing campaigns. No vendor patches have been released yet for the newly disclosed vulnerabilities, making compensating controls and network segmentation essential in the interim.

  • Dell RecoverPoint CVE-2026-22769 rated CVSS 10 โ€” maximum severity with potential for full system compromise
  • 7 critical CVEs disclosed, a 250% increase over the prior day's 2 critical vulnerabilities
  • 48 high-priority CVEs represent a 92% jump from the previous day's 25 high-severity disclosures
  • Remote code execution and authentication bypass patterns dominate, affecting WordPress, Linux kernel, and Datart deployments
  • 0% patch availability across all newly disclosed CVEs โ€” no vendor fixes released at time of publication
  • 18 actively exploited vulnerabilities span Microsoft Windows and Office, Apple OS, Google Chromium, and legacy systems including Zimbra and FreePBX

Immediate action: Prioritize reviewing exposure to Microsoft Windows and Office, Dell RecoverPoint, WordPress, and Apple systems where active exploitation is confirmed. With no patches currently available for newly disclosed vulnerabilities, implement network segmentation, restrict access to affected services, and monitor for indicators of compromise as an interim mitigation strategy.

How to read this brief

CVSS score (e.g. 9.1) โ€” severity from 0โ€“10. Red marks critical (9+), orange high (7โ€“8.9).

Exploitability โ€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical โ€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges โ€” the access they need first. No privileges means no login required.
  • No interaction / User interaction โ€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale โ€” โ€œNetwork ยท No privileges ยท No interactionโ€ is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited โ€” confirmed under attack in the wild (CISAโ€™s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS ยท Nth percentile โ€” FIRST.orgโ€™s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% โ€” a statistical signal itโ€™s unusually likely to be targeted, separate from whether attacks are confirmed.

๐Ÿ’ก Tip: Swipe CVE cards left to โญ star, right to โŒ remove

Section Navigation