Mar 20, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 3 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2023-27586 CairoSVG is an SVG converter based on Cairo, a 2D graphics library.

  • CVSS 9.9

New critical Courtbouillon Cairosvg DoS (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

High-risk exposure

CVE-2023-28424 Soko if the code that powers packages.gentoo.org.

  • CVSS 9.1

New high-severity Gentoo Soko SQL Injection — watch for exploit drops and scanner noise in the first 72 hours after disclosure.

High-risk exposure

CVE-2023-27578 Galaxy is an open-source platform for data analysis.

  • CVSS 9.1

New critical-severity CVE in today's window — elevated exposure signal, early in the lifecycle.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-27578 CVSS 9.1

Galaxy is an open-source platform for data analysis.

CVE-2023-27586 CVSS 9.9

CairoSVG is an SVG converter based on Cairo, a 2D graphics library.

CVE-2023-28424 CVSS 9.1

Soko if the code that powers packages.gentoo.org.

View critical disclosures

cvelogic Threat Intelligence