Critical exposure
CVE-2023-37286 SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key.
- CVSS 9.8
New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Three highest-priority changes — analyst brief, not a CVE dump.
Critical exposure
New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.
High-risk exposure
New high-severity Smartsoft Smartbpm.net privilege escalation — watch for exploit drops and scanner noise in the first 72 hours after disclosure.
CISA KEV — confirmed in-the-wild exploitation.
Nothing flagged in this category for this digest.
Nothing flagged in this category for this digest.
Nothing flagged in this category for this digest.
SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key.
SmartBPM.NET has a vulnerability of using hard-coded authentication key.