Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
Citrix NetScaler ADC And NetScaler Gateway added to CISA KEV — confirmed in-the-wild exploitation.
10 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Critical active threat
CVE-2023-4966Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow
Actively exploited (CISA KEV)
Listed on CISA KEV
Citrix NetScaler ADC And NetScaler Gateway Buffer Overflow is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.
New critical Ivanti Endpoint Manager Deserialization (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
CVE-2023-39332Various `node:fs` functions allow specifying paths as either strings or `Uint8Array` objects.
CVSS 9.8
New critical Fedoraproject Fedora Path Traversal (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.