Jan 16, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2026-23800 Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Esc...

  • CVSS 10
  • Potential privilege escalation to admin/root

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2025-14894 Livewire-filemanager Filemanager RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Livewire-filemanager Filemanager RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2026-23744 MCPJam inspector is the local-first development platform for MCP servers.

  • CVSS 9.8
  • Remote code execution exposure

New critical Mcpjam Inspector RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2012-10064 CVSS 9.3

Omni Secure Files plugin versions prior to 0.1.14 contain an arbitrary file upload vulnerability in the bundled plupload example endpoint.

CVE-2025-14510 CVSS 9.2

Incorrect Implementation of Authentication Algorithm vulnerability in ABB ABB Ability OPTIMAX.This issue affects ABB Ability OPTIMAX: 6.1...

CVE-2025-14894 CVSS 9.8

Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type...

CVE-2025-15403 CVSS 9.8

The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.0.7.1.

CVE-2026-21623 CVSS 9.4

Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component for Joomla.

CVE-2026-21624 CVSS 9.4

Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla.

CVE-2026-23523 CVSS 9.6

Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs.

CVE-2026-23722 CVSS 9.1

WeGIA is a Web Manager for Charitable Institutions.

CVE-2026-23744 CVSS 9.8

MCPJam inspector is the local-first development platform for MCP servers.

CVE-2026-23800 CVSS 10

Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: f...

View critical disclosures

cvelogic Threat Intelligence