Jul 17, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Adobe Commerce And Magento Open Source added to CISA KEV — confirmed in-the-wild exploitation.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2022-22948 VMware vCenter Server Incorrect Default File Permissions

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

VMware VCenter Server Info Disclosure is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2024-20419 New critical Cisco Smart Software Manager On-prem exposure disclosed.

  • CVSS 10
  • Network edge / SD-WAN deployments affected

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2024-20401 New critical Cisco Secure Email Gateway exposure disclosed.

  • CVSS 9.8
  • Network edge / SD-WAN deployments affected

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE)

VMware vCenter Server Incorrect Default File Permissions

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-4976 CVSS 9.3

A flaw exists in FlashBlade whereby a local account is permitted to authenticate to the management interface using an unintended method t...

CVE-2024-20401 CVSS 9.8

New critical Cisco Secure Email Gateway exposure disclosed.

CVE-2024-20419 CVSS 10

New critical Cisco Smart Software Manager On-prem exposure disclosed.

CVE-2024-23470 CVSS 9.6

The SolarWinds Access Rights Manager was found to be susceptible to a pre-authentication remote code execution vulnerability.

CVE-2024-23471 CVSS 9.6

The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability.

CVE-2024-23472 CVSS 9.6

SolarWinds Access Rights Manager (ARM) is susceptible to Directory Traversal vulnerability.

CVE-2024-23475 CVSS 9.6

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability.

CVE-2024-28074 CVSS 9.6

It was discovered that a previous vulnerability was not completely fixed with SolarWinds Access Rights Manager.

CVE-2024-41184 CVSS 9.8

In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur.

View critical disclosures

cvelogic Threat Intelligence