Mar 17, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2026-21994 Oracle Okit

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

High-risk exposure

CVE-2026-32292 Gl-inet Comet Gl-rm1 Firmware

  • CVSS 9.3

New critical-severity CVE in today's window — elevated exposure signal, early in the lifecycle.

High-risk exposure

CVE-2026-32295 Jetkvm Kvm

  • CVSS 9.3

New critical-severity CVE in today's window — elevated exposure signal, early in the lifecycle.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2026-21994 CVSS 9.8

Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source Projects (componen...

CVE-2026-25534 CVSS 9.1

### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddriver.

CVE-2026-25769 CVSS 9.1

Wazuh is a free and open source platform used for threat prevention, detection, and response.

CVE-2026-25770 CVSS 9.1

Wazuh is a free and open source platform used for threat prevention, detection, and response.

CVE-2026-32292 CVSS 9.3

The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess credentials.

CVE-2026-32295 CVSS 9.3

JetKVM before 0.5.4 does not rate limit login requests, enabling brute-force attempts to guess credentials.

CVE-2026-32297 CVSS 9.3

The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or system binaries.

CVE-2026-32841 CVSS 9.2

Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthenticated attackers...

CVE-2026-3564 CVSS 9

A condition in ScreenConnect may allow an actor with access to server-level cryptographic material used for authentication to obtain unau...

CVE-2026-4312 CVSS 9.3

GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to di...

View critical disclosures

cvelogic Threat Intelligence