Aug 11, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Synacor Zimbra Collaboration Suite (ZCS): 2 CVEs added to CISA KEV today.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2022-27925 Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Synacor Zimbra Collaboration Suite (ZCS) Directory Traversal is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2022-20237 Google Android RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Google Android RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-20400 In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a missing bounds check.

  • CVSS 9.8
  • Remote code execution exposure

New critical Google Android RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass

Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-20237 CVSS 9.8

In BuildDevIDResponse of miscdatabuilder.cpp, there is a possible out of bounds write due to a missing bounds check.

CVE-2022-20365 CVSS 9.8

Product: AndroidVersions: Android kernelAndroid ID: A-229632566References: N/A

CVE-2022-20378 CVSS 9.8

Product: AndroidVersions: Android kernelAndroid ID: A-234657153References: N/A

CVE-2022-20381 CVSS 9.8

Product: AndroidVersions: Android kernelAndroid ID: A-188935887References: N/A

CVE-2022-20384 CVSS 9.8

Product: AndroidVersions: Android kernelAndroid ID: A-211727306References: N/A

CVE-2022-20400 CVSS 9.8

In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a missing bounds check.

CVE-2022-20402 CVSS 9.8

Product: AndroidVersions: Android kernelAndroid ID: A-218701042References: N/A

CVE-2022-20403 CVSS 9.8

Product: AndroidVersions: Android kernelAndroid ID: A-207975764References: N/A

CVE-2022-20405 CVSS 9.8

Product: AndroidVersions: Android kernelAndroid ID: A-216363416References: N/A

CVE-2022-28755 CVSS 9.6

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a URL parsing vulnera...

View critical disclosures

cvelogic Threat Intelligence