Jul 8, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Microsoft Defender For Endpoint: public exploit or PoC linked (privilege escalation)
  • Microsoft Internet Explorer — exploitation likelihood rose sharply (EPSS 22% → 35% · rising (+13%)).
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2024-50477 Stacksmarket Stacks Mobile App Builder Auth Bypass

  • Public exploit or PoC available
  • Exploit activity linked
  • Authentication bypass — unauthenticated access risk

Stacksmarket Stacks Mobile App Builder Auth Bypass now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2025-47161 Microsoft Defender For Endpoint privilege escalation

  • Public exploit or PoC available
  • Exploit activity linked
  • Potential privilege escalation to admin/root

Microsoft Defender For Endpoint privilege escalation now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Emerging exploitation risk

CVE-2016-0068 Microsoft Internet Explorer privilege escalation

  • Exploitation likelihood sharply increased
  • Potential privilege escalation to admin/root
  • EPSS 22% → 35% · rising (+13%)

Microsoft Internet Explorer: EPSS 22% → 35% · rising (+13%) — EPSS is climbing faster than peer CVEs in this window, a leading indicator even before KEV or public exploit linkage.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2025-47228 Exploit

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell injection in the SSH connection settings allow...

CVE-2025-32462 Exploit

Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users t...

CVE-2025-32463 Exploit

Sudo Inclusion of Functionality from Untrusted Control Sphere

CVE-2025-47171 Exploit

Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.

CVE-2025-47175 Exploit

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

CVE-2025-47161 Exploit

Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

CVE-2024-50477 Exploit

Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allo...

CVE-2024-47773 Exploit

Discourse is an open source platform for community discussion.

View new exploit links

Exploitation dynamics

CVE-2016-0068 EPSS 22% → 35% · rising (+13%) CVSS 8.8

Microsoft Internet Explorer privilege escalation

CVE-2016-0069 EPSS 26% → 38% · rising (+12%) CVSS 8.8

Microsoft Internet Explorer privilege escalation

See EPSS increases

New critical disclosures

CVE-2025-21450 CVSS 9.1

Cryptographic issue occurs due to use of insecure connection method while downloading.

CVE-2025-27203 CVSS 9.6

Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary co...

CVE-2025-37103 CVSS 9.8

Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal...

CVE-2025-40714 CVSS 9.3

SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter.

CVE-2025-40715 CVSS 9.3

SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter.

CVE-2025-40716 CVSS 9.3

SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter.

CVE-2025-40717 CVSS 9.3

SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter.

CVE-2025-47981 CVSS 9.8

Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.

CVE-2025-49533 CVSS 9.8

Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could...

CVE-2025-49535 CVSS 9.3

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE')...

View critical disclosures

cvelogic Threat Intelligence