---
title: Threat Report 2/10/26
description: Key updates on Microsoft Office and Fortinet vulnerabilities, a CISA directive on unsupported devices, national cybersecurity policy changes, and a ransomware warning.
---

[HTG Threat Report ](https://www.harbortg.com/htg-threat-report)

# [Threat Report 2/10/26](https://www.harbortg.com/htg-threat-report/threat-report-2/10/26)

 Written by [Evan Kennedy](https://www.harbortg.com/htg-threat-report/author/evan-kennedy) | Feb 10, 2026 3:30:00 PM

# Microsoft Office Vulnerability Enables Security Feature Bypass

A newly identified vulnerability in Microsoft Office could allow attackers to bypass built-in security protections. Microsoft Office is widely used for everyday productivity tasks such as creating documents, managing spreadsheets, and building presentations, which makes this issue particularly impactful in business environments.

Exploitation requires an attacker to send a specially crafted Microsoft Office file and convince a user to open it. Microsoft has confirmed that the Preview Pane is **not** an attack vector for this vulnerability.

 

## **Affected Systems**

- Microsoft Office 2019 (32-bit and 64-bit) prior to 16.0.10417.20095
- Microsoft Office 2016 (32-bit and 64-bit) prior to 16.0.5539.1001

## **Risk Level**

- **Large and medium-sized organizations:** **High**
- **Small businesses:** **Medium**

## **Remediation Recommendations**

- Verify all Microsoft Office installations are fully up to date
- Apply the **Principle of Least Privilege** to reduce potential impact

## **References**

- **[https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509?utm_campaign=Threat%20Report&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-91h__O-kLrRrO4IetbZ2iODu1Ynid-E3eQt0CpU1QhBEM0_aGKwMqbAsnjWWE4nzi9BWg4)**

 

# **Fortinet Releases Guidance to Address Ongoing Exploitation of Authentication Bypass Vulnerability**

 

A newly disclosed vulnerability, **CVE-2026-24858** **(****[CWE-288: Authentication Bypass Using an Alternate Path or Channel](https://cwe.mitre.org/data/definitions/288.html?utm_campaign=Threat%20Report&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-91h__O-kLrRrO4IetbZ2iODu1Ynid-E3eQt0CpU1QhBEM0_aGKwMqbAsnjWWE4nzi9BWg4))**, allows malicious actors with a FortiCloud account and a registered device to authenticate to **other users’ devices**when FortiCloud Single Sign-On (SSO) is enabled.

 

This vulnerability affects multiple Fortinet products, including **FortiOS, FortiManager, FortiWeb, FortiProxy, and FortiAnalyzer**. Successful exploitation enables an attacker to log in to devices registered to different FortiCloud users, potentially leading to unauthorized access and configuration changes.

Notably, systems remain vulnerable to CVE-2026-24858 **even if they were fully updated** to address earlier FortiCloud SSO bypass vulnerabilities (**[CVE-2025-59718](https://www.cve.org/CVERecord?id=CVE-2025-59718&utm_campaign=Threat%20Report&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-91h__O-kLrRrO4IetbZ2iODu1Ynid-E3eQt0CpU1QhBEM0_aGKwMqbAsnjWWE4nzi9BWg4)**and** C****[VE-2025-59719](https://www.cve.org/CVERecord?id=CVE-2025-59719&utm_campaign=Threat%20Report&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-91h__O-kLrRrO4IetbZ2iODu1Ynid-E3eQt0CpU1QhBEM0_aGKwMqbAsnjWWE4nzi9BWg4)****, ****[CWE-347: Improper Verification of Cryptographic Signature](https://cwe.mitre.org/data/definitions/347.html?utm_campaign=Threat%20Report&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-91h__O-kLrRrO4IetbZ2iODu1Ynid-E3eQt0CpU1QhBEM0_aGKwMqbAsnjWWE4nzi9BWg4)****).**

 

Those earlier flaws affected FortiOS, FortiWeb, FortiProxy, and FortiSwitch Manager and allowed authentication bypass through crafted SAML messages.

Fortinet has observed the following malicious activity on devices that were previously patched for **[CVE-2025-59718](https://www.cve.org/CVERecord?id=CVE-2025-59718&utm_campaign=Threat%20Report&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-91h__O-kLrRrO4IetbZ2iODu1Ynid-E3eQt0CpU1QhBEM0_aGKwMqbAsnjWWE4nzi9BWg4)** and **[CVE-2025-59719](https://www.cve.org/CVERecord?id=CVE-2025-59719&utm_campaign=Threat%20Report&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-91h__O-kLrRrO4IetbZ2iODu1Ynid-E3eQt0CpU1QhBEM0_aGKwMqbAsnjWWE4nzi9BWg4)**:

- Unauthorized firewall configuration changes on FortiGate devices
- Unauthorized creation of user accounts
- Unauthorized VPN configuration changes granting access to newly created accounts

To mitigate active exploitation, Fortinet temporarily disabled all FortiCloud SSO authentication on **January 26**, reinstating the service on **January 27** with additional protections to prevent exploitation of vulnerable devices.

The **Cybersecurity and Infrastructure Security Agency (CISA)** added CVE-2026-24858 to its **[Known Exploited Vulnerabilities (KEV) Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?utm_campaign=Threat%20Report&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-91h__O-kLrRrO4IetbZ2iODu1Ynid-E3eQt0CpU1QhBEM0_aGKwMqbAsnjWWE4nzi9BWg4)** on January 27. CISA strongly urges organizations to inspect affected Fortinet products for indicators of compromise and to apply all available updates immediately, following Fortinet’s official guidance.

 

**Additional Resources**

- [Administrative FortiCloud SSO Authentication Bypass](https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios?utm_campaign=Threat%20Report&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-91h__O-kLrRrO4IetbZ2iODu1Ynid-E3eQt0CpU1QhBEM0_aGKwMqbAsnjWWE4nzi9BWg4)
- [Analysis of Single Sign-On Abuse on FortiOS](https://fortiguard.fortinet.com/psirt/FG-IR-26-060?utm_campaign=Threat%20Report&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-91h__O-kLrRrO4IetbZ2iODu1Ynid-E3eQt0CpU1QhBEM0_aGKwMqbAsnjWWE4nzi9BWg4)

 

# **CISA Cracks Down on End-of-Support Edge Devices**

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued [**Binding Operational Directive (BOD) 26-02**](https://www.cisa.gov/news-events/directives/bod-26-02-mitigating-risk-end-support-edge-devices?_hsmi=402399749&utm_content=402399749&utm_campaign=Threat%20Report&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-91h__O-kLrRrO4IetbZ2iODu1Ynid-E3eQt0CpU1QhBEM0_aGKwMqbAsnjWWE4nzi9BWg4), requiring Federal Civilian Executive Branch (FCEB) agencies to replace **end-of-support (EOS) edge devices** that no longer receive vendor security patches.

Under the directive, agencies must:

- Develop and submit an inventory of EOS edge devices within **three months**
- Fully replace those devices within **one year**

CISA warned that unsupported edge devices pose a serious and ongoing risk to federal networks. According to the agency, “The imminent threat of exploitation to agency information systems running EOS edge devices is substantial and constant, resulting in a significant threat to federal property.” CISA also noted ongoing, widespread exploitation campaigns by advanced threat actors, who are increasingly targeting EOS edge devices as entry points to pivot deeper into FCEB networks.

Recent public reporting has highlighted multiple vendor-specific campaigns, reinforcing concerns that threat actors are actively leveraging unsupported edge infrastructure to gain persistent access to federal environments.

While BOD 26-02 applies specifically to federal agencies, CISA emphasizes that **public- and private-sector organizations should adopt similar best practices**. Continuing to operate unsupported edge devices significantly increases exposure to exploitation and undermines overall security posture.

 

# **White House Cyber Director Launches Major Overhaul of Cybersecurity Policy**

The Trump administration’s National Cyber Director, **Harry Coker Jr.**, is preparing a significant overhaul of U.S. cybersecurity policy, with a strong focus on **private-sector collaboration** and **regulatory reform**, according to reporting by **[WebProNews](https://www.webpronews.com/white-house-cyber-director-charts-new-course-for-digital-defense-through-private-sector-partnership/?_hsmi=402028599&utm_content=402028599&utm_campaign=Threat%20Report&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-91h__O-kLrRrO4IetbZ2iODu1Ynid-E3eQt0CpU1QhBEM0_aGKwMqbAsnjWWE4nzi9BWg4)**.

The forthcoming national cybersecurity strategy is expected to streamline existing security mandates in response to long-standing concerns about overlapping and sometimes conflicting regulations. The updated approach aims to reduce compliance complexity while maintaining strong security standards.

In addition, the strategy would place greater emphasis on **improving threat intelligence sharing** between government and private-sector organizations, as well as **strengthening legal protections for companies that disclose cyber incidents**. These measures are intended to encourage transparency and faster information sharing during active cyber threats.

The Office of the National Cyber Director is currently seeking feedback from **industry stakeholders**, signaling an effort to align federal cybersecurity policy more closely with real-world operational and regulatory challenges.

# **Nitrogen Ransomware Cannot be Decrypted**

[Coveware has issued a warning](https://www.coveware.com/blog/2026/2/2/nitrogen-ransomware-esxi-malware-has-a-bug?_hsmi=401822344&utm_content=401822344&utm_campaign=Threat%20Report&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-91h__O-kLrRrO4IetbZ2iODu1Ynid-E3eQt0CpU1QhBEM0_aGKwMqbAsnjWWE4nzi9BWg4) regarding the **Nitrogen ransomware ESXi variant**, revealing a critical cryptographic flaw that makes file decryption **permanently impossible**—even for the attackers themselves. Because of this defect, victims impacted by this variant are strongly discouraged from paying the ransom, as recovery is not possible even if a decryption key is provided.

 

According to Coveware, the issue stems from a corrupted public key used during the encryption process. In a standard Curve25519 keypair, the private key is generated first, and the public key is mathematically derived from it. In this case, however, the ransomware mistakenly overwrote portions of an existing public key, creating a corrupted key that is not associated with any valid private key.

As a result, the encrypted files cannot be decrypted by anyone—attackers included—because the corresponding private key does not exist. This flaw effectively renders ransom payments futile and highlights the continued risks of relying on attacker-provided recovery mechanisms.

 

[View full post](https://www.harbortg.com/htg-threat-report/threat-report-2/10/26)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Evan Kennedy"
  },
  "dateModified" : "2026-02-10T15:30:00.759Z",
  "datePublished" : "2026-02-10T15:30:00Z",
  "headline" : "Threat Report 2/10/26",
  "image" : {
    "@type" : "ImageObject",
    "height" : 628,
    "url" : "https://5580335.fs1.hubspotusercontent-na1.net/hubfs/5580335/ThreatReport2025%20%283%29.png",
    "width" : 1200
  },
  "mainEntityOfPage" : "https://www.harbortg.com/htg-threat-report/threat-report-2/10/26",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "HTG Threat Report"
  }
}
```