TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Recorded Future Blog

February 2026 CVE Landscape: 13 Critical Vulnerabilities Mark 43% Drop from January

2026-03-12 · Read original ↗

ATT&CK techniques detected

6 predictions
T1190Exploit Public-Facing Application
99%
"stage payload delivery, with observed network communication to infrastructure associated with the threat group. unc6201 ( suspected china - nexus ) exploited cve - 2026 - 22769 to compromise dell recoverpoint for vms appliances, deploying the slaystyle web shell, brickstorm backd…"
T1190Exploit Public-Facing Application
95%
"earlier cisco saw active exploitation of an authentication bypass in catalyst sd - wan infrastructure additional affected vendors : notepad + +, apple, soliton systems k. k., google, and dell most common weakness types cwe - 78 – os command injection ( tied for most common ) cwe …"
T1195.002Compromise Software Supply Chain
84%
"replace legitimate notepad + + update packages with malicious installers, deploying cobalt strike and the chrysalis backdoor to targeted users over a six - month period. the vulnerability affects the wingup updater used by notepad + + versions prior to 8. 8. 9, which fails to cry…"
T1588.006Vulnerabilities
64%
"february 2026 cve landscape : 13 critical vulnerabilities mark 43 % drop from january february 2026 saw a 43 % decrease in high - impact vulnerabilities, with recorded future ' s insikt group® identifying 13 vulnerabilities requiring immediate remediation, down from 23 in january…"
T1554Compromise Host Software Binary
43%
"replace legitimate notepad + + update packages with malicious installers, deploying cobalt strike and the chrysalis backdoor to targeted users over a six - month period. the vulnerability affects the wingup updater used by notepad + + versions prior to 8. 8. 9, which fails to cry…"
T1588.006Vulnerabilities
35%
"chromium cwe - 416 ( use after free ) yes 12 cve - 2026 - 22769 99 dell recoverpoint for virtual machines ( rp4vms ) cwe - 798 ( use of hard - coded credentials ) no 13 cve - 2026 - 20127 99 cisco catalyst sd - wan controller and manager cwe - 287 ( improper authentication ) yes …"

Summary

February 2026 saw a 43% decrease in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 13 vulnerabilities requiring immediate remediation, down from 23 in January 2026.