Jun 9, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • SAP NetWeaver: 3 CVEs added to CISA KEV today.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2016-2386 SAP NetWeaver SQL Injection

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

SAP NetWeaver SQL Injection is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2022-29226 Envoy is a cloud-native high-performance proxy.

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2022-25152 Itarian On-premise

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-1986 CVSS 9.8

OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9.

CVE-2022-1992 CVSS 9.1

Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.

CVE-2022-25152 CVSS 9.9

The ITarian platform (SAAS / on-premise) offers the possibility to run code on agents via a function called procedures.

CVE-2022-28615 CVSS 9.1

Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided wi...

CVE-2022-29226 CVSS 10

Envoy is a cloud-native high-performance proxy.

CVE-2022-31031 CVSS 9.8

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP,...

CVE-2022-31813 CVSS 9.8

Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header...

CVE-2022-31827 CVSS 9.1

MonstaFTP v2.10.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the function performFetchRequest at HTTPFetcher.php.

CVE-2022-31830 CVSS 9.1

Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.class.php.

CVE-2022-32272 CVSS 9.8

OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorre...

View critical disclosures

cvelogic Threat Intelligence