Dec 6, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Croogo: public exploit or PoC linked (RCE)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2021-44673 Croogo RCE

  • Public exploit or PoC available
  • Exploit activity linked
  • Remote code execution exposure

Croogo RCE now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2021-40859 Auerswald Compact 5500r Firmware

  • Public exploit or PoC available
  • Exploit activity linked

Public exploit or PoC linked — exploitation bar is lower than disclosure-only CVEs.

Critical exposure

CVE-2021-31632 B2evolution Cms SQL Injection

  • CVSS 9.8

New critical B2evolution Cms SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2021-44673 Exploit

A Remote Code Execution (RCE) vulnerability exists in Croogo 3.0.2via admin/file-manager/attachments, which lets a malicoius user upload...

CVE-2021-40859 Exploit

Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web based management...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-31632 CVSS 9.8

b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section.

CVE-2021-40091 CVSS 9.8

An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654.

CVE-2021-44677 CVSS 9.8

An issue (1 of 6) was discovered in Veritas Enterprise Vault through 14.1.2.

CVE-2021-44678 CVSS 9.8

An issue (2 of 6) was discovered in Veritas Enterprise Vault through 14.1.2.

CVE-2021-44679 CVSS 9.8

An issue (3 of 6) was discovered in Veritas Enterprise Vault through 14.1.2.

CVE-2021-44680 CVSS 9.8

An issue (4 of 6) was discovered in Veritas Enterprise Vault through 14.1.2.

CVE-2021-44681 CVSS 9.8

An issue (5 of 6) was discovered in Veritas Enterprise Vault through 14.1.2.

CVE-2021-44682 CVSS 9.8

An issue (6 of 6) was discovered in Veritas Enterprise Vault through 14.1.2.

CVE-2021-44684 CVSS 9.8

naholyr github-todos 3.1.0 is vulnerable to command injection.

CVE-2021-44685 CVSS 9.8

Git-it through 4.4.0 allows OS command injection at the Branches Aren't Just For Birds challenge step.

View critical disclosures

cvelogic Threat Intelligence