Jun 2, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Atlassian Confluence Server/Data Center added to CISA KEV — confirmed in-the-wild exploitation.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2022-26134 Atlassian Confluence Server and Data Center Remote Code Execution

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV
  • Remote code execution exposure

Atlassian Confluence Server/Data Center RCE is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2021-42875 Totolink Ex1200t Firmware Command Injection

  • CVSS 9.8

New critical Totolink Ex1200t Firmware Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-45981 NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack.

  • CVSS 9.8

New critical Netscout Ngeniusone XXE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Atlassian Confluence Server and Data Center Remote Code Execution

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-33473 CVSS 9.1

An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url o...

CVE-2021-42875 CVSS 9.8

TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the file lib/cste_mod...

CVE-2021-45981 CVSS 9.8

NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack.

CVE-2021-45983 CVSS 9.8

NetScout nGeniusONE 6.3.2 allows Java RMI Code Execution.

CVE-2022-25163 CVSS 9.8

Improper Input Validation vulnerability in Mitsubishi Electric MELSEC-Q Series QJ71E71-100 first 5 digits of serial number "24061" or pri...

CVE-2022-26869 CVSS 9.8

Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability.

CVE-2022-29704 CVSS 9.8

BrowsBox CMS v4.0 was discovered to contain a SQL injection vulnerability.

CVE-2022-30234 CVSS 9.4

A CWE-798: Use of Hard-coded Credentials vulnerability exists that could allow arbitrary code to be executed when root level access is ob...

CVE-2022-31462 CVSS 9.3

Owl Labs Meeting Owl 5.2.0.15 allows attackers to control the device via a backdoor password (derived from the serial number) that can be...

CVE-2022-32019 CVSS 9.8

Car Rental Management System v1.0 is vulnerable to Arbitrary code execution via car-rental-management-system/admin/ajax.php?action=save_car.

View critical disclosures

cvelogic Threat Intelligence