logo

CISA Issues Urgent Warning on Microsoft Configuration Manager SQL Injection Vulnerability Under Active Exploitation

ID: 2d46fdcf-59fd-5624-95ac-f26834c6ef9b

STIX ID: report--2d46fdcf-59fd-5624-95ac-f26834c6ef9b

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-02-13

Date Updated: 2026-04-22

Author: Divya

...
...

CISA has added CVE-2024-43468, a critical unauthenticated SQL injection in Microsoft Configuration Manager being actively exploited in the wild, to its Known Exploited Vulnerabilities catalog; the flaw enables remote command execution and database manipulation on high-value enterprise management servers, prompting mandatory mitigation timelines and urgent patching guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.