Jan 17, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Sourcefabric Rpi-jukebox-rfid: public exploit or PoC linked (Command Injection)
  • WordPress plugin RCE/exploit activity: 2 CVEs flagged today.
  • Tricerasoft Swift Ultralite — exploitation likelihood rose sharply (EPSS 5.8% → 19% · rising (+14%)).

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2025-10327 A weakness has been identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0.

  • Public exploit or PoC available
  • Exploit activity linked

Sourcefabric Rpi-jukebox-rfid Command Injection now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2025-57174 An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4...

  • Public exploit or PoC available
  • Exploit activity linked

Public exploit or PoC linked — exploitation bar is lower than disclosure-only CVEs.

Emerging exploitation risk

CVE-2009-3253 Tricerasoft Swift Ultralite Buffer Overflow

  • Exploitation likelihood sharply increased
  • CVSS 9.3
  • EPSS 5.8% → 19% · rising (+14%)

Tricerasoft Swift Ultralite: EPSS 5.8% → 19% · rising (+14%) — EPSS is climbing faster than peer CVEs in this window, a leading indicator even before KEV or public exploit linkage.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2025-57174 Exploit

An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other pre...

CVE-2025-57176 Exploit

On Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwave antennas before 2026-03-10, the rfpiped service on TCP...

CVE-2025-10327 Exploit

A weakness has been identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0.

View new exploit links

Exploitation dynamics

CVE-2009-3253 EPSS 5.8% → 19% · rising (+14%) CVSS 9.3

Tricerasoft Swift Ultralite Buffer Overflow

CVE-2009-3254 EPSS 5.1% → 19% · rising (+14%) CVSS 9.3

Ultimatevideosite Ultimate Player Buffer Overflow

See EPSS increases

New critical disclosures

CVE-2025-10484 CVSS 9.8

The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all vers...

CVE-2025-15403 CVSS 9.8

The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.0.7.1.

View critical disclosures

cvelogic Threat Intelligence