Jun 10, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Atlassian Confluence Server/Data Center: public exploit or PoC linked (RCE)
  • 5 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2022-26134 Atlassian Confluence Server and Data Center Remote Code Execution

  • Public exploit or PoC available
  • Exploit activity linked
  • Remote code execution exposure

Atlassian Confluence Server/Data Center RCE now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2021-41754 dynamicMarkt <= 3.10 is affected by SQL injection in the parent parameter of index.php.

  • CVSS 9.8

New critical Dynamicvision Dynamicmarkt SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-41755 dynamicMarkt <= 3.10 is affected by SQL injection in the kat1 parameter of index.php.

  • CVSS 9.8

New critical Dynamicvision Dynamicmarkt SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2022-26134 Exploit

Atlassian Confluence Server and Data Center Remote Code Execution

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-41754 CVSS 9.8

dynamicMarkt <= 3.10 is affected by SQL injection in the parent parameter of index.php.

CVE-2021-41755 CVSS 9.8

dynamicMarkt <= 3.10 is affected by SQL injection in the kat1 parameter of index.php.

CVE-2021-41756 CVSS 9.8

dynamicMarkt <= 3.10 is affected by SQL injection in the kat parameter of index.php.

CVE-2022-31788 CVSS 9.8

IdeaLMS 2022 allows SQL injection via the IdeaLMS/ChatRoom/ClassAccessControl/6?isBigBlueButton=0&ClassID= pathname.

CVE-2022-32563 CVSS 9.8

An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2.

View critical disclosures

cvelogic Threat Intelligence