Jun 28, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Atlassian Data Center: public exploit or PoC linked (cross-site scripting)
  • 5 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2021-26078 Atlassian Data Center cross-site scripting

  • Public exploit or PoC available
  • Exploit activity linked

Atlassian Data Center cross-site scripting now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2020-23711 Naviwebs Navigate Cms SQL Injection

  • CVSS 9.8

New critical Naviwebs Navigate Cms SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-34187 Chamilo SQL Injection

  • CVSS 9.8

New critical Chamilo SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2021-26078 Exploit

The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6,...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-23711 CVSS 9.8

SQL Injection vulnerability in NavigateCMS 2.9 via the URL encoded GET input category in navigate.php.

CVE-2021-31337 CVSS 9.8

The Telnet service of the SIMATIC HMI Comfort Panels system component in affected products does not require authentication, which may all...

CVE-2021-34187 CVSS 9.8

main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.

CVE-2021-35456 CVSS 9.8

Online Pet Shop We App 1.0 is vulnerable to remote SQL injection and shell upload

CVE-2021-35514 CVSS 9.8

Narou (aka Narou.rb) before 3.8.0 allows Ruby Code Injection via the title name or author name of a novel.

View critical disclosures

cvelogic Threat Intelligence