Mar 18, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Microsoft SharePoint added to CISA KEV — confirmed in-the-wild exploitation.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2025-66376 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Synacor Zimbra Collaboration Suite (ZCS) XSS is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2026-32731 ApostropheCMS is an open-source content management framework.

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2026-30703 A command injection vulnerability exists in the web management interface of the WiFi Extender WDR...

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Microsoft SharePoint Deserialization of Untrusted Data

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2025-15031 CVSS 9.1

New critical Lfprojects Mlflow exposure disclosed.

CVE-2026-25873 CVSS 9.3

OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers t...

CVE-2026-30701 CVSS 9.1

The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure mechanisms (in t...

CVE-2026-30702 CVSS 9.8

The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface.

CVE-2026-30703 CVSS 9.8

A command injection vulnerability exists in the web management interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02).

CVE-2026-30704 CVSS 9.1

The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hardware pads on the PCB

CVE-2026-32633 CVSS 9.1

Glances is an open-source system cross-platform monitoring tool.

CVE-2026-32698 CVSS 9.1

OpenProject is an open-source, web-based project management software.

OpenProject is an open-source, web-based project management software.

CVE-2026-32731 CVSS 9.9

ApostropheCMS is an open-source content management framework.

View critical disclosures

cvelogic Threat Intelligence