Oct 9, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Ivanti Cloud Services Appliance (CSA): 2 CVEs added to CISA KEV today.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2024-9379 Ivanti Cloud Services Appliance (CSA) SQL Injection

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Ivanti Cloud Services Appliance (CSA) SQL Injection is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2024-9463 Palo Alto Networks Expedition OS Command Injection

  • CVSS 9.9

New critical Palo Alto Networks Expedition Command Injection (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-9518 Wpuserplus Userplus Privilege Escalation

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Wpuserplus Userplus Privilege Escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Ivanti Cloud Services Appliance (CSA) SQL Injection

Ivanti Cloud Services Appliance (CSA) OS Command Injection

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-25825 CVSS 9.8

FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be configured with t...

CVE-2024-45746 CVSS 9.8

An issue was discovered in Trusted Firmware-M through 2.1.0.

CVE-2024-47832 CVSS 9.3

ssoready is a single sign on provider implemented via docker.

CVE-2024-48949 CVSS 9.1

The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n)...

CVE-2024-8015 CVSS 9.1

In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible through object inje...

CVE-2024-9463 CVSS 9.9

Palo Alto Networks Expedition OS Command Injection

CVE-2024-9464 CVSS 9.3

An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as r...

CVE-2024-9465 CVSS 9.2

Palo Alto Networks Expedition SQL Injection

CVE-2024-9518 CVSS 9.8

The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to insufficient restric...

View critical disclosures

cvelogic Threat Intelligence