Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
Microsoft .NET Framework, SharePoint, Visual Studio: public exploit or PoC linked (RCE)
8 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Active exploit activity
CVE-2020-1147Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution
Public exploit or PoC available
Exploit activity linked
Remote code execution exposure
Microsoft .NET Framework, SharePoint, Visual Studio RCE now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.
Active exploit activity
CVE-2021-22145A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting.
Public exploit or PoC available
Exploit activity linked
Public exploit or PoC linked — exploitation bar is lower than disclosure-only CVEs.
Critical exposure
CVE-2020-14032ASRock 4x4 BOX-R1000 before BIOS P1.40 allows privilege escalation via code execution in the SMM.
CVSS 9.8
Remote code execution exposure
New critical Asrock Box-r1000 Firmware Code Execution (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.