May 4, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Linux Kernel: public exploit or PoC linked (Use-After-Free)
  • Etherpad Lite — exploitation likelihood rose sharply (EPSS 60% → 77% · rising (+17%)).
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2025-60690 Linksys E1200 Firmware Buffer Overflow

  • Public exploit or PoC available
  • Exploit activity linked

Linksys E1200 Firmware Buffer Overflow now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2026-21250 Microsoft Windows 11 24h2 privilege escalation

  • Public exploit or PoC available
  • Exploit activity linked
  • Potential privilege escalation to admin/root

Microsoft Windows 11 24h2 privilege escalation now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2018-9845 Etherpad Lite

  • Exploitation likelihood sharply increased
  • CVSS 9.8
  • EPSS 60% → 77% · rising (+17%)

Etherpad Lite: EPSS 60% → 77% · rising (+17%) — EPSS is climbing faster than peer CVEs in this window, a leading indicator even before KEV or public exploit linkage.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2026-23231 Exploit

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() nf_t...

CVE-2026-27483 Exploit

MindsDB is a platform for building artificial intelligence from enterprise data.

CVE-2025-68930 Exploit

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijacking (CSWSH) vulne...

CVE-2026-21250 Exploit

Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

CVE-2025-40271 Exploit

In the Linux kernel, the following vulnerability has been resolved: fs/proc: fix uaf in proc_readdir_de() Pde is erased from subdir rbtre...

CVE-2025-60690 Exploit

A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2....

View new exploit links

Exploitation dynamics

CVE-2018-9845 EPSS 60% → 77% · rising (+17%) CVSS 9.8

Etherpad Lite

CVE-2017-8734 EPSS 58% → 70% · rising (+12%) CVSS 7.5

Microsoft Edge Memory Corruption

See EPSS increases

New critical disclosures

CVE-2026-41922 CVSS 9.3

WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the wireless.cgi binary that all...

CVE-2026-41923 CVSS 9.3

WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the internet.cgi binary that all...

CVE-2026-41924 CVSS 9.3

WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the makeRequest.cgi binary that...

CVE-2026-41925 CVSS 9.3

WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the adm.cgi binary's reboot_time...

CVE-2026-41926 CVSS 9.3

WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the firewall.cgi binary across f...

CVE-2026-42088 CVSS 9.6

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems.

CVE-2026-42231 CVSS 9.4

n8n is an open source workflow automation platform.

CVE-2026-42232 CVSS 9.4

n8n is an open source workflow automation platform.

Nginx UI is a web user interface for the Nginx web server.

CVE-2026-42796 CVSS 9.2

Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a...

View critical disclosures

cvelogic Threat Intelligence