Aug 20, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 6 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2021-21826 Att Xmill Buffer Overflow

  • CVSS 9.8

New critical Att Xmill Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-21827 Att Xmill Buffer Overflow

  • CVSS 9.8

New critical Att Xmill Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-21828 Att Xmill Buffer Overflow

  • CVSS 9.8

New critical Att Xmill Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-18879 CVSS 9.8

Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the componen...

CVE-2020-25359 CVSS 9.1

An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6.

CVE-2020-36474 CVSS 9.8

SafeCurl before 0.9.2 has a DNS rebinding vulnerability.

CVE-2021-21826 CVSS 9.8

A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7.

CVE-2021-21827 CVSS 9.8

A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7.

CVE-2021-21828 CVSS 9.8

A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7.

View critical disclosures

cvelogic Threat Intelligence