Sep 12, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Microsoft Word: 2 CVEs added to CISA KEV today.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2023-36761 Microsoft Word Information Disclosure

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Microsoft Word Info Disclosure is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2023-3710 Honeywell Pm43 Firmware Command Injection

  • CVSS 9.9

New critical Honeywell Pm43 Firmware Command Injection (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-2071 Rockwellautomation Factorytalk View RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Rockwellautomation Factorytalk View RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Microsoft Streaming Service Proxy Privilege Escalation

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-24093 CVSS 9.1

Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability.

CVE-2023-2071 CVSS 9.8

Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticate...

CVE-2023-3710 CVSS 9.9

Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue a...

CVE-2023-39073 CVSS 9.8

An issue in SNMP Web Pro v.1.1 allows a remote attacker to execute arbitrary code and obtain senstive information via a crafted request.

CVE-2023-39150 CVSS 9.8

ConEmu before commit 230724 does not sanitize title responses correctly for control characters, potentially leading to arbitrary code exe...

CVE-2023-39637 CVSS 9.8

D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis.

CVE-2023-40784 CVSS 9.8

DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.

CVE-2023-40834 CVSS 9.8

OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthen...

CVE-2023-4501 CVSS 9.8

User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterpris...

View critical disclosures

cvelogic Threat Intelligence