Sep 1, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-36130 Hashicorp Boundary Privilege Escalation

  • CVSS 9.9
  • Potential privilege escalation to admin/root

New critical Hashicorp Boundary Privilege Escalation (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2020-35527 Netapp Ontap Select Deploy Administration Utility memory safety

  • CVSS 9.8

New critical Netapp Ontap Select Deploy Administration Utility memory safety (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-34372 Dell Powerprotect Cyber Recovery Auth Bypass

  • CVSS 9.8
  • Authentication bypass — unauthenticated access risk

New critical Dell Powerprotect Cyber Recovery Auth Bypass (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-35527 CVSS 9.8

In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.

CVE-2022-34372 CVSS 9.8

Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability.

CVE-2022-34379 CVSS 9.4

Dell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability.

CVE-2022-34380 CVSS 9.3

Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulnerability.

CVE-2022-36130 CVSS 9.9

HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated with the correct s...

CVE-2022-36601 CVSS 9.8

The Eclipse TCF debug interface in JasMiner-X4-Server-20220621-090907 and below is open on port 1534.

CVE-2022-36672 CVSS 9.8

Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file.

View critical disclosures

cvelogic Threat Intelligence