Apr 18, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Apache Tomcat — exploitation likelihood rose sharply (EPSS 37% → 67% · rising (+31%)).
  • 9 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Emerging exploitation risk

CVE-2002-1148 Apache Tomcat

  • Exploitation likelihood sharply increased
  • EPSS 37% → 67% · rising (+31%)

Apache Tomcat: EPSS 37% → 67% · rising (+31%) — EPSS is climbing faster than peer CVEs in this window, a leading indicator even before KEV or public exploit linkage.

Emerging exploitation risk

CVE-2016-5696 Google Android

  • Exploitation likelihood sharply increased
  • EPSS 29% → 52% · rising (+23%)

Google Android: EPSS 29% → 52% · rising (+23%) — EPSS is climbing faster than peer CVEs in this window, a leading indicator even before KEV or public exploit linkage.

Critical exposure

CVE-2026-40492 SAIL is a cross-platform library for loading and saving images with support for animation, metada...

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

CVE-2002-1148 EPSS 37% → 67% · rising (+31%) CVSS 5

Apache Tomcat

CVE-2016-5696 EPSS 29% → 52% · rising (+23%) CVSS 4.8

Google Android

CVE-2011-3490 EPSS 20% → 41% · rising (+21%) CVSS 10

Measuresoft Scadapro Buffer Overflow

CVE-2009-0519 EPSS 29% → 44% · rising (+15%) CVSS 9.3

Adobe Air DoS

CVE-2009-0114 EPSS 23% → 36% · rising (+13%) CVSS 5.8

Adobe Air

See EPSS increases

New critical disclosures

CVE-2026-40317 CVSS 9.3

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly.

CVE-2026-40324 CVSS 9.1

Hot Chocolate is an open-source GraphQL server.

CVE-2026-40484 CVSS 9.1

ChurchCRM is an open-source church management system.

CVE-2026-40492 CVSS 9.8

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles.

CVE-2026-40493 CVSS 9.8

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles.

CVE-2026-40494 CVSS 9.8

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles.

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly.

CVE-2026-40582 CVSS 9.1

ChurchCRM is an open-source church management system.

CVE-2026-41242 CVSS 9.4

protobufjs compiles protobuf definitions into JavaScript (JS) functions.

View critical disclosures

cvelogic Threat Intelligence