Home
» Risk & Exploitation
» Daily threat intelligence
» May 18, 2021
May 18, 2021 Cyber Threat Intelligence
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
Microsoft Exchange Server: public exploit or PoC linked (RCE)
5 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Active exploit activity
CVE-2021-26855
Microsoft Exchange Server Remote Code Execution
Public exploit or PoC available
Exploit activity linked
Enterprise mail systems at risk
Exchange-class mail edge with renewed exploit interest — historically attracts opportunistic and targeted campaigns after PoC release.
Critical exposure
CVE-2020-18178
Hongcms Project Hongcms Path Traversal
New critical Hongcms Project Hongcms Path Traversal (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
CVE-2021-31316
Control-webpanel Webpanel SQL Injection
New critical Control-webpanel Webpanel SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Active exploitation
CISA KEV — confirmed in-the-wild exploitation.
Nothing flagged in this category for this digest.
View KEV additions
Exploitation dynamics
Nothing flagged in this category for this digest.
See EPSS increases
New critical disclosures
Path Traversal in HongCMS v4.0.0 allows remote attackers to view, edit, and delete arbitrary files via a crafted POST request to the comp...
In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.
The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.
The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execut...
WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.
View critical disclosures
cvelogic
Threat Intelligence