Aug 13, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2021-37705 OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform.

  • CVSS 10
  • Potential privilege escalation to admin/root

New critical Microsoft Onefuzz privilege escalation (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2020-18753 Dcce Mac1100 Plc Firmware privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Dcce Mac1100 Plc Firmware privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-21829 Att Xmill RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Att Xmill RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-18753 CVSS 9.8

An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to gain access to the system and escalate privileges via...

CVE-2020-18758 CVSS 9.8

An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to execute arbitrary code.

CVE-2021-21829 CVSS 9.8

A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&T...

CVE-2021-21830 CVSS 9.8

A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T Labs’ Xmill 0.7.

CVE-2021-3352 CVSS 9.1

The Software Development Kit in Mitel MiContact Center Business from 8.0.0.0 through 8.1.4.1 and 9.0.0.0 through 9.3.1.0 could allow an u...

CVE-2021-34823 CVSS 9.1

The ON24 ScreenShare (aka DesktopScreenShare.app) plugin before 2.0 for macOS allows remote file access via its built-in HTTP server.

CVE-2021-36380 CVSS 9.8

Sunhillo SureLine OS Command Injection Vulnerablity

CVE-2021-36789 CVSS 9.8

The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection.

CVE-2021-37705 CVSS 10

OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform.

CVE-2021-38302 CVSS 9.8

The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection.

View critical disclosures

cvelogic Threat Intelligence