Mar 6, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 4 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2021-46704 Genieacs Command Injection

  • CVSS 9.8

New critical Genieacs Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-26495 Debian Linux Buffer Overflow

  • CVSS 9.8

New critical Debian Linux Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-26496 In nbd-server in nbd before 3.24, there is a stack-based buffer overflow.

  • CVSS 9.8

New critical Debian Linux Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-46703 CVSS 9.8

In the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .NET code in a sand...

CVE-2021-46704 CVSS 9.8

In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (li...

CVE-2022-26495 CVSS 9.8

In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow.

CVE-2022-26496 CVSS 9.8

In nbd-server in nbd before 3.24, there is a stack-based buffer overflow.

View critical disclosures

cvelogic Threat Intelligence