logo

January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day

ID: 62873cdd-8de2-5b13-964b-f55d647607dd

STIX ID: report--62873cdd-8de2-5b13-964b-f55d647607dd

Feed Name: Recorded Future Blog

Threat Score
90/100

Date Published: 2026-02-24

Date Updated: 2026-04-29

...
...

**Recorded Future Insikt Group: January 2026 — High-impact active exploitation across enterprise software**: The report details 23 vulnerabilities exploited in the wild during January 2026, highlights APT28's zero-day campaign (CVE-2026-21509) that delivered email-collection and backdoor implants, documents widespread authentication-bypass and pre-authentication RCE flaws (SmarterMail, Ivanti, Modular DS, Cisco, etc.), lists IoCs and Nuclei templates, and provides immediate remediation and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.