Jan 5, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2025-59157 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.

  • CVSS 9.9

New critical Coollabs Coolify Command Injection (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2025-64420 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.

  • CVSS 9.9
  • Potential privilege escalation to admin/root

New critical Coollabs Coolify privilege escalation (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2025-64419 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.

  • CVSS 9.6

New critical disclosure (CVSS 9.6) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2025-27807 CVSS 9.1

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 13...

CVE-2025-59156 CVSS 9.4

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.

CVE-2025-59157 CVSS 9.9

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.

CVE-2025-59158 CVSS 9.4

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.

CVE-2025-64419 CVSS 9.6

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.

CVE-2025-64420 CVSS 9.9

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.

CVE-2025-64424 CVSS 9.4

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.

CVE-2025-67397 CVSS 9.1

An issue in Passy v.1.6.3 allows a remote authenticated attacker to execute arbitrary commands via a crafted HTTP request using a specifi...

CVE-2025-68428 CVSS 9.2

jsPDF is a library to generate PDFs in JavaScript.

CVE-2026-0625 CVSS 9.3

Multiple D-Link DSL/DIR/DNS devices contain an authentication bypass and improper access control vulnerability in the dnscfg.cgi endpoint...

View critical disclosures

cvelogic Threat Intelligence