Aug 4, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Synacor Zimbra Collaboration Suite (ZCS) added to CISA KEV — confirmed in-the-wild exploitation.
  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2022-27924 Synacor Zimbra Collaboration Suite (ZCS) Command Injection

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Synacor Zimbra Collaboration Suite (ZCS) Command Injection is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2022-25168 Apache Hadoop RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Apache Hadoop RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-2651 Joinbookwyrm Bookwyrm Auth Bypass

  • CVSS 9.8
  • Authentication bypass — unauthenticated access risk

New critical Joinbookwyrm Bookwyrm Auth Bypass (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Synacor Zimbra Collaboration Suite (ZCS) Command Injection

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-25168 CVSS 9.8

Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell.

CVE-2022-2651 CVSS 9.8

Authentication Bypass by Primary Weakness in GitHub repository bookwyrm-social/bookwyrm prior to 0.4.5.

CVE-2022-32964 CVSS 9.8

OMICARD EDM’s API function has insufficient validation for user input.

CVE-2022-34970 CVSS 9.8

Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h.

CVE-2022-34993 CVSS 9.8

Totolink A3600R_Firmware V4.1.2cu.5182_B20201102 contains a hard code password for root in /etc/shadow.sample.

CVE-2022-35143 CVSS 9.8

Renato v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force attacks.

View critical disclosures

cvelogic Threat Intelligence