Home
» Risk & Exploitation
» Daily threat intelligence
» Oct 20, 2022
Oct 20, 2022 Cyber Threat Intelligence
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
Synacor Zimbra Collaboration Suite (ZCS) added to CISA KEV — confirmed in-the-wild exploitation.
7 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Critical active threat
CVE-2021-3493
Linux Kernel Privilege Escalation
Actively exploited (CISA KEV)
Listed on CISA KEV
Potential privilege escalation to admin/root
Linux Kernel Privilege Escalation is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.
Critical exposure
CVE-2022-27624
Synology Diskstation Manager
New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.
Critical exposure
CVE-2022-27625
Synology Diskstation Manager
New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.
Active exploitation
CISA KEV — confirmed in-the-wild exploitation.
Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload
Linux Kernel Privilege Escalation
View KEV additions
Exploitation dynamics
Nothing flagged in this category for this digest.
See EPSS increases
New critical disclosures
A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the packet decryption funct...
A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the message processing func...
A vulnerability regarding concurrent execution using shared resource with improper synchronization ('Race Condition') is found in the ses...
Shinken Solutions Shinken Monitoring Version 2.4.3 affected is vulnerable to Incorrect Access Control.
Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.js.
Best Student Result Management System v1.0 is vulnerable to SQL Injection via /upresult/upresult/notice-details.php?nid=.
Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.
View critical disclosures
cvelogic
Threat Intelligence