Jan 9, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2025-65091 XWiki Full Calendar Macro displays objects from the wiki on the calendar.

  • CVSS 10

New critical Xwiki Full Calendar Macro SQL Injection (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2025-69425 The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command executio...

  • CVSS 10
  • Potential privilege escalation to admin/root

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2025-69426 The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credent...

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-36875 CVSS 9.3

AccessAlly WordPress plugin versions prior to 3.3.2 contain an unauthenticated arbitrary PHP code execution vulnerability in the Login Wi...

CVE-2025-65091 CVSS 10

XWiki Full Calendar Macro displays objects from the wiki on the calendar.

CVE-2025-69425 CVSS 10

The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2004 running with...

CVE-2025-69426 CVSS 10

The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating system user accoun...

CVE-2025-69542 CVSS 9.8

A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07.

CVE-2025-70161 CVSS 9.8

EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection.

CVE-2026-22584 CVSS 9.8

Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Exe...

CVE-2026-22600 CVSS 9.1

OpenProject is an open-source, web-based project management software.

CVE-2026-22688 CVSS 9.9

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval.

View critical disclosures

cvelogic Threat Intelligence