May 26, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Barracuda Networks Email Security Gateway (ESG) Appliance added to CISA KEV — confirmed in-the-wild exploitation.
  • Tuzitio Camaleon Cms: public exploit or PoC linked (CVSS 9.8)
  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2023-2868 Barracuda Networks ESG Appliance Improper Input Validation

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Barracuda Networks Email Security Gateway (ESG) Appliance Command Injection is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical active threat

CVE-2023-30145 Tuzitio Camaleon Cms

  • Public exploit or PoC available
  • CVSS 9.8
  • Exploit activity linked

Public exploit or PoC linked — exploitation bar is lower than disclosure-only CVEs.

Critical exposure

CVE-2023-2825 An issue has been discovered in GitLab CE/EE affecting only version 16.0.0.

  • CVSS 10

New critical Gitlab Path Traversal (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Barracuda Networks ESG Appliance Improper Input Validation

View KEV additions

Exploit & PoC activity

CVE-2023-30145 Exploit CVSS 9.8

Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-46887 CVSS 9.8

Lack of length check vulnerability in the HW_KEYMASTER module.

CVE-2022-46945 CVSS 9.1

Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagVisHoverUrl.php.

CVE-2022-48478 CVSS 9.8

The facial recognition TA of some products lacks memory length verification.

CVE-2022-48479 CVSS 9.8

The facial recognition TA of some products has the out-of-bounds memory read vulnerability.

CVE-2023-2825 CVSS 10

An issue has been discovered in GitLab CE/EE affecting only version 16.0.0.

CVE-2023-32321 CVSS 9.8

CKAN is an open-source data management system for powering data hubs and data portals.

View critical disclosures

cvelogic Threat Intelligence