Mar 16, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Wing FTP Server added to CISA KEV — confirmed in-the-wild exploitation.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2025-47813 Wing FTP Server Information Disclosure

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Wing FTP Server Info Disclosure is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2026-32621 Apollo Federation is an architecture for declaratively composing APIs into a unified graph.

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2025-69809 P2r3 Bareiron RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical P2r3 Bareiron RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2025-62319 CVSS 9.8

Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (T...

CVE-2025-69808 CVSS 9.1

An out-of-bounds memory access (OOB) in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to access sensitive information and...

CVE-2025-69809 CVSS 9.8

A write-what-where condition in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to write arbitrary values to memory, enablin...

CVE-2025-69902 CVSS 9.8

A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to execute arbitrary...

CVE-2026-23489 CVSS 9.1

Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms.

CVE-2026-27962 CVSS 9.1

Authlib is a Python library which builds OAuth and OpenID Connect servers.

CVE-2026-28430 CVSS 9.3

Chamilo LMS is a learning management system.

CVE-2026-32621 CVSS 9.9

Apollo Federation is an architecture for declaratively composing APIs into a unified graph.

CVE-2026-32626 CVSS 9.6

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting.

CVE-2026-4177 CVSS 9.1

YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow i...

View critical disclosures

cvelogic Threat Intelligence