Apr 7, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Veritas Backup Exec Agent: 3 CVEs added to CISA KEV today.
  • Mercurycom Mac1200r Firmware: public exploit or PoC linked (Directory Traversal)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2019-1388 Microsoft Windows Certificate Dialog Privilege Escalation

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV
  • Potential privilege escalation to admin/root

Microsoft Windows Privilege Escalation is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Active exploit activity

CVE-2021-27825 Mercurycom Mac1200r Firmware Directory Traversal

  • Public exploit or PoC available
  • Exploit activity linked

Mercurycom Mac1200r Firmware Directory Traversal now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2023-26848 Totolink A7100ru Firmware Command Injection

  • CVSS 9.8

New critical Totolink A7100ru Firmware Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Arm Mali GPU Kernel Driver Information Disclosure

Veritas Backup Exec Agent Improper Authentication

Microsoft Windows Certificate Dialog Privilege Escalation

View KEV additions

Exploit & PoC activity

CVE-2021-27825 Exploit

A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-static/ URL.

CVE-2023-24788 Exploit

NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/sales/customer_del...

CVE-2023-27010 Exploit

Wondershare Dr.Fone v12.9.6 was discovered to contain weak permissions for the service WsDrvInst.

CVE-2023-27290 Exploit

Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not curre...

CVE-2020-35391 Exploit

Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a d...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-26848 CVSS 9.8

TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the org parameter at setting/delS...

CVE-2023-26978 CVSS 9.8

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pppoeAcName parameter at /sett...

CVE-2023-27017 CVSS 9.8

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45DC58 function.

CVE-2023-27018 CVSS 9.8

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45EC1C function.

CVE-2023-27019 CVSS 9.8

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_458FBC function.

CVE-2023-27020 CVSS 9.8

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the saveParentControlInfo function.

CVE-2023-27021 CVSS 9.8

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the formSetFirewallCfg function.

CVE-2023-27033 CVSS 9.8

Prestashop cdesigner v3.1.3 to v3.1.8 was discovered to contain a code injection vulnerability via the component CdesignerSaverotateModul...

CVE-2023-28706 CVSS 9.8

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This i...

CVE-2023-29478 CVSS 9.8

BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on...

View critical disclosures

cvelogic Threat Intelligence