Mar 29, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Sas\/intrnet — exploitation likelihood rose sharply (EPSS 55% → 74% · rising (+19%)).
  • 8 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Emerging exploitation risk

CVE-2021-41569 Sas\/intrnet

  • Exploitation likelihood sharply increased
  • EPSS 55% → 74% · rising (+19%)

Sas\/intrnet: EPSS 55% → 74% · rising (+19%) — EPSS is climbing faster than peer CVEs in this window, a leading indicator even before KEV or public exploit linkage.

Emerging exploitation risk

CVE-2021-41460 Shopex Ecshop SQL Injection

  • Exploitation likelihood sharply increased
  • EPSS 28% → 45% · rising (+16%)

Shopex Ecshop: EPSS 28% → 45% · rising (+16%) — EPSS is climbing faster than peer CVEs in this window, a leading indicator even before KEV or public exploit linkage.

Critical exposure

CVE-2026-0558 New critical Lollms DoS disclosed.

  • CVSS 9.8

New critical Lollms DoS (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

CVE-2021-41569 EPSS 55% → 74% · rising (+19%) CVSS 7.5

Sas\/intrnet

CVE-2021-41460 EPSS 28% → 45% · rising (+16%) CVSS 7.5

Shopex Ecshop SQL Injection

CVE-2022-24082 EPSS 31% → 46% · rising (+14%) CVSS 9.8

Pega Infinity

CVE-2020-25206 EPSS 19% → 30% · rising (+10%) CVSS 7.2

Mimosa B5 Firmware Command Injection

See EPSS increases

New critical disclosures

CVE-2026-32915 CVSS 9.3

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagents control surfac...

CVE-2026-32918 CVSS 9.2

OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandboxed subagents to a...

CVE-2026-32922 CVSS 9.4

OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing...

CVE-2026-32978 CVSS 9.4

OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable file operands for...

CVE-2026-32987 CVSS 9.3

OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts.

CVE-2026-4176 CVSS 9.8

Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Comp...

CVE-2026-4851 CVSS 9.8

GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization.

View critical disclosures

cvelogic Threat Intelligence