Aug 16, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Citrix Content Collaboration added to CISA KEV — confirmed in-the-wild exploitation.
  • 6 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2023-24489 Citrix Content Collaboration ShareFile Improper Access Control

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Confirmed in-the-wild exploitation per CISA KEV — active threat momentum, not theoretical risk.

Critical exposure

CVE-2023-35893 Ibm Security Guardium

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2020-26037 Evenbalance Punkbuster Directory Traversal

  • CVSS 9.8

New critical Evenbalance Punkbuster Directory Traversal (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Citrix Content Collaboration ShareFile Improper Access Control

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-26037 CVSS 9.8

Directory Traversal vulnerability in Server functionalty in Even Balance Punkbuster version 1.902 before 1.905 allows remote attackers to...

CVE-2023-33663 CVSS 9.8

In the module “Customization fields fee for your store” (aicustomfee) from ai-dev module for PrestaShop, an attacker can perform SQL inje...

CVE-2023-35893 CVSS 9.9

IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system...

CVE-2023-38894 CVSS 9.8

A Prototype Pollution issue in Cronvel Tree-kit v.0.7.4 and before allows a remote attacker to execute arbitrary code via the extend func...

CVE-2023-39115 CVSS 9.8

install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document.

CVE-2023-39846 CVSS 9.8

An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token.

View critical disclosures

cvelogic Threat Intelligence