Mar 15, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Adobe ColdFusion added to CISA KEV — confirmed in-the-wild exploitation.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2023-26360 Adobe ColdFusion Deserialization of Untrusted Data

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV
  • Remote code execution exposure

Adobe ColdFusion RCE is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2020-27507 Kamailio Buffer Overflow

  • CVSS 9.8

New critical Kamailio Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-23150 SA-WR915ND router firmware v17.35.1 was discovered to be vulnerable to code execution.

  • CVSS 9.8
  • Remote code execution exposure

New critical Lancombg Sa-wr915nd Firmware Code Execution (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Adobe ColdFusion Deserialization of Untrusted Data

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-27507 CVSS 9.8

The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow t...

CVE-2022-44580 CVSS 9.1

SQL Injection (SQLi) vulnerability in RichPlugins Plugin for Google Reviews plugin <= 2.2.3 versions.

CVE-2023-23150 CVSS 9.8

SA-WR915ND router firmware v17.35.1 was discovered to be vulnerable to code execution.

CVE-2023-24468 CVSS 9.8

Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2

CVE-2023-24726 CVSS 9.8

Art Gallery Management System v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter on the enquiry page.

CVE-2023-24795 CVSS 9.8

Command execution vulnerability was discovered in JHR-N916R router firmware version<=21.11.1.1483.

CVE-2023-25344 CVSS 9.8

An issue was discovered in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to execute arbitrary code via crafted Object.p...

CVE-2023-26784 CVSS 9.8

SQL Injection vulnerability found in Kirin Fortress Machine v.1.7-2020-0610 allows attackers to execute arbitrary code via the /admin.php...

CVE-2023-28461 CVSS 9.8

Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function

View critical disclosures

cvelogic Threat Intelligence