Feb 28, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Emc Retrospect Client — exploitation likelihood rose sharply (EPSS 32% → 49% · rising (+17%)).

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Emerging exploitation risk

CVE-2006-2391 Emc Retrospect Client Buffer Overflow

  • Exploitation likelihood sharply increased
  • EPSS 32% → 49% · rising (+17%)

Emc Retrospect Client: EPSS 32% → 49% · rising (+17%) — EPSS is climbing faster than peer CVEs in this window, a leading indicator even before KEV or public exploit linkage.

Emerging exploitation risk

CVE-2006-0396 Apple Mac Os X Buffer Overflow

  • Exploitation likelihood sharply increased
  • EPSS 23% → 37% · rising (+14%)

Apple Mac Os X: EPSS 23% → 37% · rising (+14%) — EPSS is climbing faster than peer CVEs in this window, a leading indicator even before KEV or public exploit linkage.

High-risk exposure

CVE-2026-3010 Microchip Timepictra XSS

  • CVSS 9.3

New high-severity Microchip Timepictra XSS — watch for exploit drops and scanner noise in the first 72 hours after disclosure.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

CVE-2006-2391 EPSS 32% → 49% · rising (+17%) CVSS 7.5

Emc Retrospect Client Buffer Overflow

CVE-2006-0396 EPSS 23% → 37% · rising (+14%) CVSS 5.1

Apple Mac Os X Buffer Overflow

See EPSS increases

New critical disclosures

CVE-2026-2844 CVSS 9.3

Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Manipulation.This iss...

CVE-2026-3010 CVSS 9.3

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimePictra allows...

View critical disclosures

cvelogic Threat Intelligence