Sep 27, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2023-5183 Illumio Core Policy Compute Engine Deserialization

  • CVSS 9.9

New critical Illumio Core Policy Compute Engine Deserialization (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-5168 Mozilla Firefox Out-of-Bounds Write

  • CVSS 9.8

New critical Mozilla Firefox Out-of-Bounds Write (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-5172 Mozilla Firefox Use-After-Free

  • CVSS 9.8

New critical Mozilla Firefox Use-After-Free (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-20252 CVSS 9.8

New critical Cisco Catalyst Sd-wan Manager exposure disclosed.

CVE-2023-41449 CVSS 9.8

An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.

CVE-2023-44080 CVSS 9.8

An issue in PGYER codefever v.2023.8.14-2ce4006 allows a remote attacker to execute arbitrary code via a crafted request to the branchLis...

CVE-2023-4523 CVSS 9.4

Real Time Automation 460 Series products with versions prior to v8.9.8 are vulnerable to cross-site scripting, which could allow an attac...

CVE-2023-5168 CVSS 9.8

A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a po...

CVE-2023-5172 CVSS 9.8

A hashtable in the Ion Engine could have been mutated while there was a live interior reference, leading to a potential use-after-free an...

CVE-2023-5174 CVSS 9.8

If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting...

CVE-2023-5175 CVSS 9.8

During process shutdown, it was possible that an `ImageBitmap` was created that would later be used after being freed from a different co...

CVE-2023-5176 CVSS 9.8

Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2.

CVE-2023-5183 CVSS 9.9

Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE.

View critical disclosures

cvelogic Threat Intelligence