May 1, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • TP-Link Archer AX21 added to CISA KEV — confirmed in-the-wild exploitation.
  • 4 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2021-45046 Apache Log4j2 Deserialization of Untrusted Data

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Apache Log4j2 Deserialization is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2022-35898 Opentext Bizmanager

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2022-45802 Apache Streampark

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-35898 CVSS 9.8

OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation.

CVE-2022-45802 CVSS 9.8

Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing use...

CVE-2022-46365 CVSS 9.1

Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server...

CVE-2023-29635 CVSS 9.8

File upload vulnerability in Antabot White-Jotter v0.2.2, allows remote attackers to execute malicious code via the file parameter to fun...

View critical disclosures

cvelogic Threat Intelligence