Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
Ivanti Endpoint Manager Mobile (EPMM) added to CISA KEV — confirmed in-the-wild exploitation.
Bludit: public exploit or PoC linked (RCE)
Maxum Development Corporation Rumpus Ftp Server — exploitation likelihood rose sharply (EPSS 6.9% → 24% · rising (+17%)).
10 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Critical active threat
CVE-2026-6973Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation
Actively exploited (CISA KEV)
Listed on CISA KEV
Remote code execution exposure
Ivanti Endpoint Manager Mobile (EPMM) RCE is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.
Thingsboard SSRF now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.
Emerging exploitation risk
CVE-2007-0019Maxum Development Corporation Rumpus Ftp Server Buffer Overflow
Exploitation likelihood sharply increased
EPSS 6.9% → 24% · rising (+17%)
Maxum Development Corporation Rumpus Ftp Server: EPSS 6.9% → 24% · rising (+17%) — EPSS is climbing faster than peer CVEs in this window, a leading indicator even before KEV or public exploit linkage.