Apr 28, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Microsoft Windows added to CISA KEV — confirmed in-the-wild exploitation.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2024-1708 ConnectWise ScreenConnect Path Traversal

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

ConnectWise ScreenConnect Path Traversal is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2025-60889 Stellar-group Hpx Deserialization

  • CVSS 9.8

New critical Stellar-group Hpx Deserialization (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2026-24178 Nvidia Nvflare Code Execution

  • CVSS 9.8
  • Remote code execution exposure

New critical Nvidia Nvflare Code Execution (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2025-60889 CVSS 9.8

Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary...

CVE-2026-24178 CVSS 9.8

NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may...

CVE-2026-27760 CVSS 9.2

OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated a...

CVE-2026-3893 CVSS 9.4

The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network access to directly access and modi...

CVE-2026-41386 CVSS 9.1

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device role...

CVE-2026-41446 CVSS 9.2

Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only t...

CVE-2026-41873 CVSS 9.8

** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Ma...

CVE-2026-5779 CVSS 9.4

An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/user/updateUserProfile'...

CVE-2026-7321 CVSS 9.6

Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component.

CVE-2026-7333 CVSS 9.6

Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a cr...

View critical disclosures

cvelogic Threat Intelligence