Nov 28, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 2 material risk changes today across KEV, exploits, critical disclosures, and EPSS movers.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2021-44077 Zoho ManageEngine ServiceDesk Plus Remote Code Execution

  • CVSS 9.8
  • Remote code execution exposure

New critical Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-44093 Zrlog

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-44077 CVSS 9.8

Zoho ManageEngine ServiceDesk Plus Remote Code Execution

CVE-2021-44093 CVSS 9.8

A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit...

View critical disclosures

cvelogic Threat Intelligence