Jul 1, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 5 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2023-22814 Westerndigital My Cloud Os Auth Bypass

  • CVSS 10
  • Authentication bypass — unauthenticated access risk

New critical Westerndigital My Cloud Os Auth Bypass (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-28323 Ivanti Endpoint Manager Deserialization

  • CVSS 9.8

New critical Ivanti Endpoint Manager Deserialization (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-28324 Ivanti Endpoint Manager RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Ivanti Endpoint Manager RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-22814 CVSS 10

An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to ca...

CVE-2023-28323 CVSS 9.8

A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights.

CVE-2023-28324 CVSS 9.8

A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remot...

CVE-2023-28365 CVSS 9.1

A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems allows applicatio...

UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB.

View critical disclosures

cvelogic Threat Intelligence