ThreatScope by DIAMATIX
Monthly Cyber Risk Overview – February 2026
🎧 Listen to this February ThreatScope (audio brief)
February 2026 confirmed a continued escalation of high-impact vulnerabilities and persistent ransomware activity across industries.
The month was marked by:
Multiple CVEs with CVSS scores between 9.0 and 10.0
Several CVSS 10.0 vulnerabilities enabling full system compromise
Continued ransomware diversification across sectors
Supply-chain and developer-targeted malware campaigns
A large-scale data breach with national impact
This monthly overview consolidates the most critical technical exposures and threat patterns observed during February.
Critical Vulnerabilities Overview (February 2026)
| CVE | Severity | Affected Area | Risk Category |
|---|---|---|---|
| CVE-2026-25049 | 9.4 | n8n | System Command Execution |
| CVE-2026-25253 | 8.8 | OpenClaw | Remote Code Execution |
| CVE-2025-15027 | 9.8 | WordPress | Privilege Escalation |
| CVE-2026-21643 | 9.8 | Fortinet | SQL Injection |
| CVE-2026-21510 | 8.8 | Microsoft Windows | Security Feature Bypass |
| CVE-2026-26221 | 10.0 | Hyland OnBase | Remote Code Execution |
| CVE-2026-1357 | 9.8 | WordPress | Arbitrary File Upload |
| CVE-2026-1615 | 9.8 | jsonpath | Arbitrary Code Injection |
| CVE-2025-65717 | 9.1 | VS Code | Critical Vulnerability |
| CVE-2025-65716 | 8.8 | VS Code | Critical Vulnerability |
| CVE-2025-65715 | 7.8 | VS Code | Critical Vulnerability |
| CVE-2025-14009 | 10.0 | NLTK | Remote Code Execution |
| CVE-2025-30411 | 10.0 | Acronis | Improper Authentication |
| CVE-2025-30412 | 10.0 | Acronis | Improper Authentication |
| CVE-2025-30416 | 10.0 | Acronis | Improper Authentication |
| CVE-2026-2577 | 10.0 | Session Hijacking | |
| CVE-2026-22769 | 10.0 | Dell | Unauthenticated Remote Root Access |
| CVE-2026-26030 | 10.0 | Microsoft Semantic Kernel | Remote Code Execution |
| CVE-2026-20127 | 10.0 | Cisco | Zero-Day Authentication Bypass |
| CVE-2026-28363 | 9.9 | OpenClaw | Validation Bypass |
Key Vulnerability Patterns Observed
1. Enterprise Platform Exposure
High-severity vulnerabilities impacted widely used enterprise platforms including Cisco SD-WAN, Hyland OnBase, Fortinet products, Microsoft components, and Acronis.
Authentication bypass and improper access control remained dominant themes.
2. Developer Ecosystem Risk
Critical vulnerabilities affected:
VS Code
jsonpath
NLTK downloader
Microsoft Semantic Kernel
Developer tools and AI frameworks continue to represent high-trust execution environments. Compromise in these layers often cascades into production systems.
3. Web Application & CMS Risk
WordPress plugins were affected by:
Privilege escalation
Arbitrary file upload vulnerabilities
CMS ecosystems remain high-volume exploitation targets due to their broad attack surface.
4. Zero-Day & Authentication Failures
Multiple CVEs scored 10.0, including:
Cisco Zero-Day
WhatsApp session hijack
Dell unauthenticated root access
Acronis improper authentication flaws
These vulnerabilities require minimal exploitation complexity and enable full compromise scenarios.
Ransomware Activity – February 2026
Ransomware activity remained highly active.
According to tracking data:
680 victim organizations were publicly listed
54 distinct ransomware groups were active
Most Active Groups
Qilin led with 104 victims for the second consecutive month
TheGentlemen nearly doubled its activity compared to January
Established actors such as CL0P, Play, Akira, and LockBit maintained strong operational presence
Most Targeted Industries
Manufacturing
Healthcare (incidents nearly doubled month-over-month)
Ransomware operations remain diversified, persistent, and industry-targeted.
Malware Activity Trends
February malware activity demonstrated evolution across multiple vectors.
Developer-Targeted Supply Chain Campaigns
Malicious repositories disguised as legitimate Next.js projects were used to deploy in-memory malware and persistent access tooling.
Advanced Persistent Threat Campaigns
Operation Olalampo introduced new malware variants leveraging messaging platforms like Telegram for command-and-control communication.
Ransomware-Linked Malware Evolution
Families such as Reynolds incorporated BYOVD techniques to disable endpoint detection systems, blurring the line between malware and extortion frameworks.
Mobile & IoT Threat Expansion
New Android malware families such as Keenadu were identified, reinforcing cross-platform risk exposure.
Malware delivery increasingly combines automation, AI-assisted social engineering, and phishing techniques.
Incident of the Month – Conduent Data Breach
A major data breach involving Conduent Business Services affected tens of millions of individuals.
Key details:
Unauthorized access persisted for nearly three months
At least 15.4 million individuals affected in Texas alone
Over 10.5 million impacted in Oregon
Safepay ransomware group claimed theft of over 8 terabytes of data
Exfiltrated data included:
Names
Social Security numbers
Addresses
Medical histories
Health insurance information
The incident demonstrates the impact of prolonged unauthorized access combined with large-scale data processing environments.
Recommended Protection Measures
Security Controls
Endpoint Detection and Response (EDR)
Anti-ransomware behavioral monitoring
Patch management for operating systems and third-party software
Email security and URL filtering
Immutable and regularly tested backups
Operational Implementation
These controls can be centrally managed to enhance visibility, reduce response time, and improve resilience across distributed environments.
Strategic Observations for February 2026
Authentication failures remain the fastest path to compromise
Developer tooling and AI frameworks are emerging high-impact attack surfaces
Ransomware ecosystems remain diversified and stable in volume
Large-scale data breaches continue to expose systemic control weaknesses
Patch velocity and privilege control remain decisive risk differentiators
ThreatScope by DIAMATIX focuses on vulnerability clustering, operational impact, and execution-layer risk — not isolated headlines.
Trusted · Innovative · Vigilant






