Dec 12, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Google Chromium added to CISA KEV — confirmed in-the-wild exploitation.
  • 6 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2018-4063 Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV
  • Remote code execution exposure

Sierra Wireless AirLink ALEOS RCE is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2025-67728 Fireshare facilitates self-hosted media and link sharing.

  • CVSS 9.8

New critical Shaneisrael Fireshare Path Traversal (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2025-54947 Apache Streampark

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-58299 CVSS 9.3

PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execute arbitrary code.

CVE-2025-54947 CVSS 9.8

In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists.

CVE-2025-58130 CVSS 9.1

Insufficiently Protected Credentials vulnerability in Apache Fineract.

CVE-2025-65854 CVSS 9.8

Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full a...

CVE-2025-67728 CVSS 9.8

Fireshare facilitates self-hosted media and link sharing.

View critical disclosures

cvelogic Threat Intelligence