Jul 29, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Atlassian Confluence added to CISA KEV — confirmed in-the-wild exploitation.
  • Asus Aura Ready Game Software Development Kit: public exploit or PoC linked (privilege escalation)
  • 5 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2022-26138 Atlassian Questions For Confluence App Hard-coded Credentials

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Confirmed in-the-wild exploitation per CISA KEV — active threat momentum, not theoretical risk.

Active exploit activity

CVE-2022-35411 Rpc.py Project Rpc.py RCE

  • Public exploit or PoC available
  • Exploit activity linked
  • Remote code execution exposure

Rpc.py Project Rpc.py RCE now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2022-22280 Sonicwall Analytics SQL Injection

  • CVSS 9.8

New critical Sonicwall Analytics SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Atlassian Questions For Confluence App Hard-coded Credentials

View KEV additions

Exploit & PoC activity

CVE-2022-35899 Exploit

There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4.

CVE-2022-29593 Exploit

relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post requests without the ne...

CVE-2022-35411 Exploit

rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-1277 CVSS 9.4

Inavitas Solar Log product has an unauthenticated SQL Injection vulnerability.

CVE-2022-22280 CVSS 9.8

Improper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerability, impacting Soni...

CVE-2022-34496 CVSS 9.8

Hiby R3 PRO firmware v1.5 to v1.7 was discovered to contain a file upload vulnerability via the file upload feature.

CVE-2022-34531 CVSS 9.8

DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php.

CVE-2022-35643 CVSS 9.1

IBM PowerVM VIOS 3.1 could allow a remote attacker to tamper with system configuration or cause a denial of service.

View critical disclosures

cvelogic Threat Intelligence