Feb 27, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • ZK Framework AuUploader added to CISA KEV — confirmed in-the-wild exploitation.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2022-36537 ZK Framework AuUploader Unspecified

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Confirmed in-the-wild exploitation per CISA KEV — active threat momentum, not theoretical risk.

Critical exposure

CVE-2022-26760 A memory corruption issue was addressed with improved state management.

  • CVSS 9.8

New critical Apple Ipados Memory Corruption (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-48255 There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325.

  • CVSS 9.8
  • Remote code execution exposure

New critical Huawei Bisheng-wnm Firmware RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-26760 CVSS 9.8

A memory corruption issue was addressed with improved state management.

CVE-2022-46723 CVSS 9.8

This issue was addressed with improved checks.

CVE-2022-48255 CVSS 9.8

There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325.

CVE-2022-48259 CVSS 9.8

There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325.

CVE-2022-48283 CVSS 9.8

A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability.

CVE-2022-48284 CVSS 9.8

A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability.

CVE-2023-23513 CVSS 9.8

A buffer overflow issue was addressed with improved memory handling.

CVE-2023-24253 CVSS 9.8

Domotica Labs srl Ikon Server before v2.8.6 was discovered to contain a SQL injection vulnerability.

CVE-2023-24258 CVSS 9.8

SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter.

CVE-2023-25234 CVSS 9.8

Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInterface.

View critical disclosures

cvelogic Threat Intelligence