Mar 23, 2026 Cyber Threat Intelligence
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
- 10 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Critical exposure
CVE-2026-4001
The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execu...
- CVSS 9.8
- Internet-facing CMS deployments affected
New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.
Critical exposure
CVE-2026-33211
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines.
New critical Linuxfoundation Tekton Pipelines Path Traversal (CVSS 9.6) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
High-risk exposure
CVE-2026-33634
Aquasecurity Trivy Embedded Malicious Code
New critical-severity CVE in today's window — elevated exposure signal, early in the lifecycle.
Active exploitation
CISA KEV — confirmed in-the-wild exploitation.
Nothing flagged in this category for this digest.
View KEV additions
Exploitation dynamics
Nothing flagged in this category for this digest.
See EPSS increases
New critical disclosures
Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments.
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement...
Citrix NetScaler Out-of-Bounds Read
Mantis Bug Tracker (MantisBT) is an open source issue tracker.
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines.
Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface.
Aquasecurity Trivy Embedded Malicious Code
WWBN AVideo is an open source video platform.
The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includin...
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM.
View critical disclosures
cvelogic
Threat Intelligence