Mar 24, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2026-4725 Sandbox escape due to use-after-free in the Graphics: Canvas2D component.

  • CVSS 10

New critical Mozilla Firefox Use-After-Free (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2026-28858 A buffer overflow was addressed with improved bounds checking.

  • CVSS 9.8

New critical Apple Ipados Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2026-4729 Memory safety bugs present in Firefox 148 and Thunderbird 148.

  • CVSS 9.8

New critical Mozilla Firefox Memory Corruption (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted data.

CVE-2026-20688 CVSS 9.3

A path handling issue was addressed with improved validation.

CVE-2026-2417 CVSS 9.3

A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version 2.15.3 could allo...

CVE-2026-28827 CVSS 9.3

A parsing issue in the handling of directory paths was addressed with improved path validation.

CVE-2026-28858 CVSS 9.8

A buffer overflow was addressed with improved bounds checking.

CVE-2026-33322 CVSS 9.2

MinIO is a high-performance object storage system.

CVE-2026-33340 CVSS 9.1

LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems.

CVE-2026-33419 CVSS 9.1

MinIO is a high-performance object storage system.

CVE-2026-4725 CVSS 10

Sandbox escape due to use-after-free in the Graphics: Canvas2D component.

CVE-2026-4729 CVSS 9.8

Memory safety bugs present in Firefox 148 and Thunderbird 148.

View critical disclosures

cvelogic Threat Intelligence