3 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Critical active threat
CVE-2019-0344SAP Commerce Cloud Deserialization of Untrusted Data
Actively exploited (CISA KEV)
Listed on CISA KEV
SAP Commerce Cloud Deserialization is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.
Critical exposure
CVE-2024-42017An issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11.
CVSS 10
Potential privilege escalation to admin/root
New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.
Critical exposure
CVE-2024-46293Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control.
CVSS 9.8
Potential privilege escalation to admin/root
New critical Oretnom23 Online Medicine Ordering System privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.