February 21 is shaping up as one of the denser security days of 2026. BeyondTrust's CVE-2026-1731 (CVSS 9.9) has moved from disclosure to full active exploitation — Palo Alto Networks Unit 42 confirmed attackers are using it for network recon, web shell deployment, C2 infrastructure, lateral movement, and data exfiltration across financial services, healthcare, legal, and higher ed sectors in the US, France, Germany, Australia, and Canada. That's a broad target spread for a single vulnerability in under a week.
Roundcube is the second CVSS 9.9 of the cycle. CISA formally added CVE-2025-49113 (deserialization RCE via unvalidated _from parameter) and CVE-2025-68461 (XSS via SVG animate tag) to the KEV catalog. Dubai-based FearsOff reports attackers diffed and weaponized CVE-2025-49113 within 48 hours of public disclosure — that's an alarmingly fast exploitation pipeline. The patch existed since June 2025 but clearly hasn't rolled out widely enough.
Supply chain took another hit with Cline CLI 2.3.0. A compromised npm publish token was used to push a modified package.json with a postinstall script that silently installed OpenClaw, the self-hosted autonomous AI agent, on every developer machine that ran npm install. No additional malicious behavior confirmed beyond the unauthorized install — but unauthorized AI agent deployment on dev systems is a significant trust violation. Meanwhile, Anthropic announced Claude Code Security, an AI-powered codebase vulnerability scanner entering limited preview for Enterprise and Team customers. Timing is not coincidental — this is the race playing out in real time.