May 20, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Google Chromium V8 added to CISA KEV — confirmed in-the-wild exploitation.
  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2023-43208 NextGen Healthcare Mirth Connect Deserialization of Untrusted Data

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV
  • Remote code execution exposure

NextGen Healthcare Mirth Connect RCE is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2024-4985 Github Enterprise Server Auth Bypass

  • CVSS 10
  • Authentication bypass — unauthenticated access risk

New critical Github Enterprise Server Auth Bypass (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-4323 A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3.

  • CVSS 9.8
  • Remote code execution exposure

New critical Treasuredata Fluent Bit RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

NextGen Healthcare Mirth Connect Deserialization of Untrusted Data

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-24294 CVSS 9.8

A Prototype Pollution issue in Blackprint @blackprint/engine v.0.9.0 allows an attacker to execute arbitrary code via the _utils.setDeepP...

CVE-2024-34947 CVSS 9.4

Quanxun Huiju Network Technology (Beijing) Co.,Ltd IK-Q3000 3.7.10 x64 Build202401261655 was discovered to be vulnerable to an ICMP redir...

CVE-2024-35571 CVSS 9.8

Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.

CVE-2024-35580 CVSS 9.8

Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.

CVE-2024-35960 CVSS 9.1

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Properly link new fs rules into the tree Previously, add_ru...

CVE-2024-4323 CVSS 9.8

A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3.

CVE-2024-4985 CVSS 10

An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authenticati...

View critical disclosures

cvelogic Threat Intelligence