Hello! I'm a Colorkrew infrastructure and security engineer. There was Valentine's Day in February. Did you eat chocolate? I received the chocolate from my mother safely, so I enjoyed it.
So, we have summarized the vulnerabilities that need to be addressed as we continued last month.
For those involved in SOC/security operations, we will identify the most recent vulnerabilities to watchCybersecurity
and the Known Exploited Vulnerbilities Catalog published by the Infrastructure Security Agency (CISA) and the Common Vulnerabilities and Exposures (CVEs) published by The MITRE Corporation Based on Records, we have written explanations + how to deal with it. Please take advantage of this to reduce the operational burden while visualizing and prioritizing risks.
What is Known Exploited Vulnerabilities Catalog?
The Known Exploited Vulnerabilities (KEV) Catalog is a list of "Vulnerabilities Confirmed to Have Actually Exploited" published by CISA. Therefore, it can be used as a criterion for quickly responding to vulnerabilities that are actually used in cyberattacks.
What is Common Vulnerabilities and Exposures?
Common Vulnerabilities and Exposures (CVEs) are identifiers assigned to vulnerabilities in individual products published by The MITRE Corporation. An organization of security professionals, such as security vendors, product development vendors, and researchers, evaluates reported vulnerabilities and assigns identifiers.
Overview of each vulnerability and how to address it
CVE-2026-20700
Product/Scope of Influence
- macOS 26.3 or earlier
- watchOS 26.3 or earlier
- visionOS 26.3 or earlier
- iOS/iPadOS 26.3 or earlier
- tvOS 26.3 or earlier
CVSS Score 7.8
Overview/Key Points
The target of this vulnerability is dyld (Dynamic Link Editor) running on Apple's operating system. It is a component that loads, links, and prepares the required shared libraries (dylibs) when the app is launched. An attacker with memory write privileges could execute arbitrary code.
Points to Deal with
Security patches for the above vulnerabilities have already been distributed.
Update each product version to 26.3 (latest as of 2026/02/11) or later.
References
CVE-2026-24858
Product/Scope of Influence
- FortiManager
- 7.6.0~7.6.5
- 7.4.0~7.4.9
- 7.2.0~7.2.11
- 7.0.0~7.0.15
- FortiOS
- 7.6.0~7.6.5
- 7.4.0~7.4.10
- 7.2.0~7.2.12
- 7.0.0~7.0.18
- FortiProxy
- 7.6.0~7.6.4
- 7.4.0~7.4.12
- 7.2.0~7.2.15
- 7.0.0~7.0.22
- FortiAnalyzer
- 7.6.0~7.6.5
- 7.4.0~7.4.9
- 7.2.0~7.2.11
- 7.0.0~7.0.15
- FortiWeb
- 8.0.0~8.0.3
- 7.6.0~7.6.6
- 7.4.0~7.4.11
CVSS score 9.4
Overview/Key Points
A vulnerability has been identified in Fortinet products that allows Fortinet products to log in to other devices registered with other accounts if they have a Forti iCloud account and a registered device. This vulnerability would not be exploited as it is, but could be exploited if "Allow administrative login using FortiCloud SSO" is enabled.
Points to Deal with
Update to the latest version of each product
- FortiManager
- 7.6.6~
- 7.4.10~
- 7.2.12~
- 7.0.16~
- FortiOS
- 7.6.6~
- 7.4.11~
- 7.2.13~
- 7.0.19~
- FortiProxy
- 7.6.5~
- 7.4.13~
- 7.2.16~
- 7.0.23~
- FortiAnalyzer
- 7.6.6~
- 7.4.10~
- 7.2.12~
- 7.0.16~
- FortiWeb
- 8.0.4~
- 7.6.7~
- 7.4.12~
References
CVE-2026-21509
Product/Scope of Influence
- Microsoft 365 Apps for Enterprise ~16.0.1
- Microsoft Office 2016 16.0.0 ~ 16.0.5539.1001
- Microsoft Office 2019 19.0.0 ~ 16.0.10417.20095
- Microsoft Office LTSC 2021 ~16.0.1
- Microsoft Office LTSC 2024 ~16.0.0
CVSS Score 7.8
Overview/Key Points
This is a vulnerability related to a security feature in a Microsoft Office product. If an attacker changes security-related inputs to a target product, it could be possible to bypass security features.
Points to Deal with
- If you are using Microsoft 365 Apps and Microsoft Office 2021~, you will need to restart the server with a fix on the server side.
- If you are using Microsoft 2016 and Microsoft 2019, security patches are required. If patching is not possible, it can be avoided by applying a registry key. For details, please refer to the official MS documentation.
References
What Colorkrew can help Colorkrew can help ColorkrewSecurity provides SOC services that support attack detection and CSIRT response to vulnerabilities such as the above.
If you have any requests such as "I want to reduce the operational burden" or "I want to quickly detect cyber attacks", please feel free to contact us. Let's strengthen your company's security operations together.