May 18, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Microsoft Exchange Server: public exploit or PoC linked (RCE)
  • 5 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2021-26855 Microsoft Exchange Server Remote Code Execution

  • Public exploit or PoC available
  • Exploit activity linked
  • Enterprise mail systems at risk

Exchange-class mail edge with renewed exploit interest — historically attracts opportunistic and targeted campaigns after PoC release.

Critical exposure

CVE-2020-18178 Hongcms Project Hongcms Path Traversal

  • CVSS 9.8

New critical Hongcms Project Hongcms Path Traversal (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-31316 Control-webpanel Webpanel SQL Injection

  • CVSS 9.8

New critical Control-webpanel Webpanel SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2021-26855 Exploit

Microsoft Exchange Server Remote Code Execution

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-18178 CVSS 9.8

Path Traversal in HongCMS v4.0.0 allows remote attackers to view, edit, and delete arbitrary files via a crafted POST request to the comp...

CVE-2020-20951 CVSS 9.8

In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.

CVE-2021-31316 CVSS 9.8

The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.

CVE-2021-31324 CVSS 9.8

The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execut...

CVE-2021-32305 CVSS 9.8

WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.

View critical disclosures

cvelogic Threat Intelligence