Apr 11, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Microsoft Active Directory: 2 CVEs added to CISA KEV today.
  • Franklinfueling Colibri Firmware: public exploit or PoC linked (Path Traversal)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2020-2509 QNAP Network-Attached Storage (NAS) Command Injection

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

QNAP Network-Attached Storage (NAS) Command Injection is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Active exploit activity

CVE-2021-46417 Franklinfueling Colibri Firmware Path Traversal

  • Public exploit or PoC available
  • Exploit activity linked

Franklinfueling Colibri Firmware Path Traversal now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2022-1161 Rockwellautomation Compact Guardlogix 5370 Firmware

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Microsoft Active Directory Domain Services Privilege Escalation

Microsoft Active Directory Domain Services Privilege Escalation

Checkbox Survey Deserialization of Untrusted Data

QNAP Network-Attached Storage (NAS) Command Injection

Telerik UI for ASP.NET AJAX Unrestricted File Upload

View KEV additions

Exploit & PoC activity

CVE-2021-46416 Exploit

Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to inse...

CVE-2021-46417 Exploit

Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin Fue...

CVE-2021-46418 Exploit

An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.

CVE-2021-46419 Exploit

An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-37291 CVSS 9.8

An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter i...

CVE-2021-38125 CVSS 9.8

Unauthenticated remote code execution in Micro Focus Operations Bridge containerized, affecting versions 2021.05, 2021.08, and newer vers...

CVE-2021-46742 CVSS 9.1

The multi-window module has a vulnerability of unauthorized insertion and tampering of Settings.Secure data.Successful exploitation of th...

CVE-2022-0949 CVSS 9.8

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does not properly saniti...

CVE-2022-1161 CVSS 10

An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Con...

CVE-2022-1297 CVSS 9.1

Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8.

CVE-2022-22258 CVSS 9.8

The Wi-Fi module has an event notification vulnerability.Successful exploitation of this vulnerability may allow third-party applications...

CVE-2022-22954 CVSS 9.8

VMware Workspace ONE Access and Identity Manager Server-Side Template Injection

CVE-2022-27115 CVSS 9.8

In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.

CVE-2022-27577 CVSS 9.1

The vulnerability in the MSC800 in all versions before 4.15 allows for an attacker to predict the TCP initial sequence number.

View critical disclosures

cvelogic Threat Intelligence