Jul 15, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Wordpress Popular Posts Project Wordpress Popular Posts: public exploit or PoC linked (RCE)
  • 4 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2021-22555 Linux Kernel Heap Out-of-Bounds Write

  • Public exploit or PoC available
  • Exploit activity linked

Linux Kernel Memory Corruption now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2021-25161 Arubanetworks Instant XSS

  • Public exploit or PoC available
  • Exploit activity linked

Arubanetworks Instant XSS now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2021-25320 Rancher

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2021-42362 Exploit

The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found...

CVE-2021-25155 Exploit

A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba...

CVE-2021-25156 Exploit

A remote arbitrary directory create vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba I...

CVE-2021-25157 Exploit

A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant...

CVE-2021-25158 Exploit

A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant...

CVE-2021-25159 Exploit

A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba...

CVE-2021-25160 Exploit

A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba...

CVE-2021-25161 Exploit

A remote cross-site scripting (xss) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba I...

CVE-2021-25162 Exploit

A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Ar...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-11633 CVSS 9.8

The Zscaler Client Connector for Windows prior to 2.1.2.74 had a stack based buffer overflow when connecting to misconfigured TLS servers.

CVE-2021-0276 CVSS 9.8

A stack-based Buffer Overflow vulnerability in Juniper Networks SBR Carrier with EAP (Extensible Authentication Protocol) authentication...

CVE-2021-25320 CVSS 9.9

A Improper Access Control vulnerability in Rancher, allows users in the cluster to make request to cloud providers by creating requests w...

CVE-2021-34690 CVSS 9.8

iDrive RemotePC before 7.6.48 on Windows allows authentication bypass.

View critical disclosures

cvelogic Threat Intelligence