Apr 20, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Cisco Catalyst SD-WAN Manger: 3 CVEs added to CISA KEV today.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2024-27199 JetBrains TeamCity Relative Path Traversal

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

JetBrains TeamCity Path Traversal is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2026-30269 Doorman Privilege Escalation

  • CVSS 9.9
  • Potential privilege escalation to admin/root

New critical Doorman Privilege Escalation (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2026-32604 Spinnaker is an open source, multi-cloud continuous delivery platform.

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs

Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format

Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor

Quest KACE Systems Management Appliance (SMA) Improper Authentication

Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2026-29646 CVSS 9.8

In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to the supervisor int...

CVE-2026-29649 CVSS 9.8

NEMU contains an implementation flaw in its RISC-V Hypervisor CSR handling where henvcfg[7:4] (CBIE/CBCFE/CBZE-related fields) is incorre...

CVE-2026-30269 CVSS 9.9

Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a non-admin privil...

CVE-2026-32311 CVSS 9.3

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification.

CVE-2026-32604 CVSS 9.9

Spinnaker is an open source, multi-cloud continuous delivery platform.

CVE-2026-32613 CVSS 9.9

Spinnaker is an open source, multi-cloud continuous delivery platform.

CVE-2026-39109 CVSS 9.4

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username paramet...

OpenClaw before 2026.3.31 contains a sandbox bypass vulnerability allowing attackers to escalate privileges via heartbeat context inherit...

CVE-2026-5450 CVSS 9.8

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a forma...

CVE-2026-6257 CVSS 9.2

Vvveb CMS v1.0.8.2 contains a remote code execution vulnerability in its media management functionality where a missing return statement...

View critical disclosures

cvelogic Threat Intelligence