Mar 9, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Kofax Printix: public exploit or PoC linked (Privilege Escalation)
  • 4 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2022-0824 Webmin RCE

  • Public exploit or PoC available
  • Exploit activity linked
  • Remote code execution exposure

Webmin RCE now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2022-25090 Kofax Printix Privilege Escalation

  • Public exploit or PoC available
  • Exploit activity linked
  • Potential privilege escalation to admin/root

Kofax Printix Privilege Escalation now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2022-22805 Schneider-electric Scl Series 1029 Ups Firmware RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Schneider-electric Scl Series 1029 Ups Firmware RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2022-25090 Exploit

Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure permissions, lead...

CVE-2022-0824 Exploit

Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-0482 CVSS 9.1

Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.

CVE-2022-0715 CVSS 9.1

A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a...

CVE-2022-22805 CVSS 9.8

A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause remote code execu...

CVE-2022-22806 CVSS 9.8

A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a...

View critical disclosures

cvelogic Threat Intelligence