May 16, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Zyxel Multiple Firewalls added to CISA KEV — confirmed in-the-wild exploitation.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2022-30525 Zyxel Multiple Firewalls OS Command Injection

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Zyxel Multiple Firewalls Command Injection is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2022-23658 Arubanetworks Clearpass Policy Manager Auth Bypass

  • CVSS 10
  • Authentication bypass — unauthenticated access risk

New critical Arubanetworks Clearpass Policy Manager Auth Bypass (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-23660 Arubanetworks Clearpass Policy Manager Auth Bypass

  • CVSS 10
  • Authentication bypass — unauthenticated access risk

New critical Arubanetworks Clearpass Policy Manager Auth Bypass (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-1586 CVSS 9.1

An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_co...

CVE-2022-1587 CVSS 9.1

An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compil...

CVE-2022-23658 CVSS 10

A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and bel...

CVE-2022-23660 CVSS 10

A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and bel...

CVE-2022-23661 CVSS 9.1

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9...

CVE-2022-23662 CVSS 9.1

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9...

CVE-2022-23663 CVSS 9.1

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9...

CVE-2022-23664 CVSS 9.1

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9...

CVE-2022-23665 CVSS 9.1

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9...

CVE-2022-23666 CVSS 9.1

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9...

View critical disclosures

cvelogic Threat Intelligence