logo

CISA flags critical Microsoft SCCM flaw as exploited in attacks

ID: 23950efa-f0a0-5d94-997e-82da660c1222

STIX ID: report--23950efa-f0a0-5d94-997e-82da660c1222

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-02-13

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA has ordered U.S. federal agencies to urgently patch Microsoft Configuration Manager for CVE-2024-43468, a critical unauthenticated SQL injection that can lead to remote code execution; Synacktiv published PoC exploit code in November 2024 and CISA now reports active in-the-wild exploitation, prompting immediate mitigation under BOD 22-01.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.