← Back to News
AI Analysis by The Wire
February 21, 2026 Focus: CYBERSECURITY Impact: 9/10

CVSS 9.9 Double Tap: BeyondTrust Actively Exploited, Roundcube Weaponized in 48 Hours — Anthropic Fires Back with AI Defense

February 21 is shaping up as one of the denser security days of 2026. BeyondTrust's CVE-2026-1731 (CVSS 9.9) has moved from disclosure to full active exploitation — Palo Alto Networks Unit 42 confirmed attackers are using it for network recon, web shell deployment, C2 infrastructure, lateral movement, and data exfiltration across financial services, healthcare, legal, and higher ed sectors in the US, France, Germany, Australia, and Canada. That's a broad target spread for a single vulnerability in under a week.

Roundcube is the second CVSS 9.9 of the cycle. CISA formally added CVE-2025-49113 (deserialization RCE via unvalidated _from parameter) and CVE-2025-68461 (XSS via SVG animate tag) to the KEV catalog. Dubai-based FearsOff reports attackers diffed and weaponized CVE-2025-49113 within 48 hours of public disclosure — that's an alarmingly fast exploitation pipeline. The patch existed since June 2025 but clearly hasn't rolled out widely enough.

Supply chain took another hit with Cline CLI 2.3.0. A compromised npm publish token was used to push a modified package.json with a postinstall script that silently installed OpenClaw, the self-hosted autonomous AI agent, on every developer machine that ran npm install. No additional malicious behavior confirmed beyond the unauthorized install — but unauthorized AI agent deployment on dev systems is a significant trust violation. Meanwhile, Anthropic announced Claude Code Security, an AI-powered codebase vulnerability scanner entering limited preview for Enterprise and Team customers. Timing is not coincidental — this is the race playing out in real time.

Impact Score
9/10
Key Stories
BeyondTrust CVE-2026-1731 Actively Exploited for Backdoors and Data Exfiltration
The Hacker News / Palo Alto Unit 42
CISA Adds Two Roundcube Flaws to KEV — CVE-2025-49113 Weaponized in 48 Hours
The Hacker News / CISA
Cline CLI 2.3.0 Supply Chain Attack — OpenClaw Silently Installed on Dev Systems
The Hacker News
Anthropic Launches Claude Code Security — AI-Powered Vulnerability Scanning
The Hacker News / Anthropic
Trump Global Tariffs Struck Down by US Supreme Court
BBC / Hacker News
Analyst Take
The 48-hour weaponization window on Roundcube CVE-2025-49113 is the stat of this cycle. Public disclosure to active exploitation in two days means the patch-to-exploit gap has effectively collapsed for high-value vulnerabilities. Organizations are no longer operating in a grace period — they need same-day patching discipline or assume compromise. BeyondTrust's exploitation profile is equally concerning: the attacker is running full-kill-chain operations across six countries simultaneously, not opportunistic scanning. That's a well-resourced threat actor with clear objectives. Anthropic dropping Claude Code Security in this exact window is a calculated signal — AI as a defensive layer is no longer theoretical. The race between AI-assisted attack and AI-assisted defense is now measurably underway.