Sep 27, 2023 Cyber Threat Intelligence
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
- 10 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Critical exposure
CVE-2023-5183
Illumio Core Policy Compute Engine Deserialization
New critical Illumio Core Policy Compute Engine Deserialization (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
CVE-2023-5168
Mozilla Firefox Out-of-Bounds Write
New critical Mozilla Firefox Out-of-Bounds Write (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
CVE-2023-5172
Mozilla Firefox Use-After-Free
New critical Mozilla Firefox Use-After-Free (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Active exploitation
CISA KEV — confirmed in-the-wild exploitation.
Nothing flagged in this category for this digest.
View KEV additions
Exploitation dynamics
Nothing flagged in this category for this digest.
See EPSS increases
New critical disclosures
New critical Cisco Catalyst Sd-wan Manager exposure disclosed.
An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.
An issue in PGYER codefever v.2023.8.14-2ce4006 allows a remote attacker to execute arbitrary code via a crafted request to the branchLis...
Real Time Automation 460 Series products with versions prior to v8.9.8 are vulnerable to cross-site scripting, which could allow an attac...
A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a po...
A hashtable in the Ion Engine could have been mutated while there was a live interior reference, leading to a potential use-after-free an...
If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting...
During process shutdown, it was possible that an `ImageBitmap` was created that would later be used after being freed from a different co...
Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2.
Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE.
View critical disclosures
cvelogic
Threat Intelligence