Jun 28, 2021 Cyber Threat Intelligence
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
- Atlassian Data Center: public exploit or PoC linked (cross-site scripting)
- 5 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Active exploit activity
CVE-2021-26078
Atlassian Data Center cross-site scripting
- Public exploit or PoC available
- Exploit activity linked
Atlassian Data Center cross-site scripting now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.
Critical exposure
CVE-2020-23711
Naviwebs Navigate Cms SQL Injection
New critical Naviwebs Navigate Cms SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
New critical Chamilo SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Active exploitation
CISA KEV — confirmed in-the-wild exploitation.
Nothing flagged in this category for this digest.
View KEV additions
Exploit & PoC activity
The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6,...
View new exploit links
Exploitation dynamics
Nothing flagged in this category for this digest.
See EPSS increases
New critical disclosures
SQL Injection vulnerability in NavigateCMS 2.9 via the URL encoded GET input category in navigate.php.
The Telnet service of the SIMATIC HMI Comfort Panels system component in affected products does not require authentication, which may all...
main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.
Online Pet Shop We App 1.0 is vulnerable to remote SQL injection and shell upload
Narou (aka Narou.rb) before 3.8.0 allows Ruby Code Injection via the title name or author name of a novel.
View critical disclosures
cvelogic
Threat Intelligence